{"data":{"id":"02d27193-77c4-4dcd-aaef-bfabdd92e1df","title":"CVE-2026-76395: In Splunk AI Toolkit versions below 6.0.0, a user who holds the \"power\" Splunk role could execute arbitrary code on the ","summary":"Splunk AI Toolkit versions before 6.0.0 have a vulnerability where users with the \"power\" role can run arbitrary code (commands the attacker chooses) on the Splunk server by uploading a specially crafted model file. The problem occurs because the toolkit deserializes (converts stored data back into usable form) untrusted data without checking for hidden malicious code in pickle format (Python's method for storing objects).","solution":"Upgrade Splunk AI Toolkit to version 6.0.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76395","publishedAt":"2026-08-19T22:17:26.023Z","cveId":"CVE-2026-76395","cweIds":["CWE-502"],"cvssScore":"8.8","cvssSeverity":"high","severity":"high","attackType":["model_poisoning"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Splunk","Splunk AI Toolkit","Splunk Machine Learning Toolkit"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-19T22:17:26.023Z","capecIds":["CAPEC-586"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}