{"data":{"id":"a06e81ef-1b68-4428-872e-4d45b560bbfb","title":"CVE-2026-76391: In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the \"admin\" or \"power\" Splunk roles could run search","summary":"In Splunk AI Toolkit versions before 6.0.0, there is a privilege escalation vulnerability (a security flaw where a user gains higher access levels than they should have) in the Agent Run History feature. Users without admin or power roles could run searches with system-level privileges, access other users' data, and delete search jobs by exploiting how the system replaces user credentials with a system authentication token.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76391","publishedAt":"2026-08-19T22:17:25.487Z","cveId":"CVE-2026-76391","cweIds":["CWE-863"],"cvssScore":"8.3","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Splunk AI Toolkit"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-19T22:17:25.487Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}