Splunk
Splunk AI Toolkit: vulnerabilities and CVEs
Splunk AI Toolkit has 12 published vulnerabilities, 12 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs12
Last 12 months12
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76399 | High (8.1) | 0.35% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search… |
| CVE-2026-76398 | Medium (4.3) | 0.25% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer… |
| CVE-2026-76397 | High (8.1) | 0.35% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is… |
| CVE-2026-76396 | High (7.5) | 0.32% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper… |
| CVE-2026-76395 | High (8.8) | 0.65% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of… |
| CVE-2026-76394 | High (8.3) | 0.35% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data… |
| CVE-2026-76393 | Medium (5.9) | 0.18% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model… |
| CVE-2026-76392 | Medium (5.4) | 0.23% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials… |
| CVE-2026-76391 | High (8.3) | 0.47% | — | Aug 19, 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or… |
| CVE-2026-20266 | Critical (9.1) | 0.63% | — | Jun 17, 2026 | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an… |
| CVE-2026-20265 | Medium (4.3) | 0.22% | — | Jun 17, 2026 | In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker… |
| CVE-2026-20238 | Medium (6.5) | 0.32% | — | May 20, 2026 | In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.