{"data":{"id":"6432ba9d-aba6-439d-8a90-091432bb6bb4","title":"CVE-2026-76394: In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the \"admin\" or \"power\" Splunk roles c","summary":"Splunk AI Toolkit versions before 6.0.0 have a security flaw where users without admin permissions can control containers and access sensitive data through the REST API (a method for software to communicate over the internet). This happens because the API doesn't properly check whether users have permission to perform these actions.","solution":"Upgrade to Splunk AI Toolkit version 6.0.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76394","publishedAt":"2026-08-19T22:17:25.870Z","cveId":"CVE-2026-76394","cweIds":["CWE-862"],"cvssScore":"8.3","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Splunk","Splunk AI Toolkit"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-19T22:17:25.870Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}