{"data":{"id":"c05bf3e3-f0da-4f49-9fa7-0c4dc274d719","title":"CVE-2026-76393: In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe","summary":"In Splunk AI Toolkit versions before 6.0.0, a race condition (a flaw where the order of simultaneous operations causes unexpected behavior) allows a user to overwrite a model that another user is uploading by sending a competing upload request with the same model name. This happens because the toolkit does not verify that the uploaded content actually belongs to the request that creates the model lookup entry (a database record linking a model name to its contents), potentially allowing an attacker to inject malicious content.","solution":"Upgrade to Splunk AI Toolkit version 6.0.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76393","publishedAt":"2026-08-19T22:17:25.737Z","cveId":"CVE-2026-76393","cweIds":["CWE-362"],"cvssScore":"5.9","cvssSeverity":"medium","severity":"medium","attackType":["model_theft"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Splunk AI Toolkit"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-19T22:17:25.737Z","capecIds":["CAPEC-26","CAPEC-29"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}