« Back to list

Splunk

Splunk AI Toolkit: vulnerabilities and CVEs

Splunk AI Toolkit has 12 published vulnerabilities, 12 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs12
Last 12 months12
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76399High (8.1)0.35%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search…
CVE-2026-76398Medium (4.3)0.25%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer…
CVE-2026-76397High (8.1)0.35%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is…
CVE-2026-76396High (7.5)0.32%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper…
CVE-2026-76395High (8.8)0.65%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of…
CVE-2026-76394High (8.3)0.35%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data…
CVE-2026-76393Medium (5.9)0.18%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model…
CVE-2026-76392Medium (5.4)0.23%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials…
CVE-2026-76391High (8.3)0.47%—Aug 19, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or…
CVE-2026-20266Critical (9.1)0.63%—Jun 17, 2026
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an…
CVE-2026-20265Medium (4.3)0.22%—Jun 17, 2026
In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker…
CVE-2026-20238Medium (6.5)0.32%—May 20, 2026
In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services6
  2. T1059 Command and Scripting Interpreter3
  3. T1068 Exploitation for Privilege Escalation1
  4. T1078 Valid Accounts1
  5. T1565.002 Transmitted Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Splunk