Vulnerabilities
Summary — last 7 days
New vulnerabilities3,060▲ 560 vs. last week
Critical / high1,458▲ 280 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
12 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (8.1) | 0.35% | — | Splunk AI Toolkit | 8/19/2026 | 8/26/2026 | In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is… | |
| Analyzed | Medium (4.3) | 0.25% | — | Splunk AI Toolkit | 8/19/2026 | 8/24/2026 | In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history… | |
| Analyzed | High (8.1) | 0.35% | — | Splunk AI Toolkit | 8/19/2026 | 8/21/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes… | |
| Analyzed | High (7.5) | 0.32% | — | Splunk AI Toolkit | 8/19/2026 | 8/21/2026 | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as… | |
| Analyzed | High (8.8) | 0.65% | — | Splunk AI Toolkit | 8/19/2026 | 8/26/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix… | |
| Analyzed | High (8.3) | 0.35% | — | Splunk AI Toolkit | 8/19/2026 | 8/26/2026 | In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because… | |
| Analyzed | Medium (5.9) | 0.18% | — | Splunk AI Toolkit | 8/19/2026 | 8/26/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model lookup entry to reference attacker-controlled content. The race condition is possible because Splunk… | |
| Analyzed | Medium (5.4) | 0.23% | — | Splunk AI Toolkit | 8/19/2026 | 8/26/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores credentials for connected container… | |
| Undergoing Analysis | High (8.3) | 0.47% | — | Splunk AI Toolkit | 8/19/2026 | 8/26/2026 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege… | |
| Analyzed | Critical (9.1) | 0.63% | — | Splunk AI Toolkit | 6/17/2026 | 6/22/2026 | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings… | |
| Analyzed | Medium (4.3) | 0.22% | — | Splunk AI Toolkit | 6/17/2026 | 6/22/2026 | In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration. The vulnerability exists because of an insecure… | |
| Analyzed | Medium (6.5) | 0.32% | — | Splunk AI Toolkit | 5/20/2026 | 7/23/2026 | In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.<br><br>The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies… |