CVE-2026-76395: In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the
Summary
Splunk AI Toolkit versions before 6.0.0 have a vulnerability where users with the "power" role can run arbitrary code (commands the attacker chooses) on the Splunk server by uploading a specially crafted model file. The problem occurs because the toolkit deserializes (converts stored data back into usable form) untrusted data without checking for hidden malicious code in pickle format (Python's method for storing objects).
Solution / Mitigation
Upgrade Splunk AI Toolkit to version 6.0.0 or later.
Vulnerability Details
8.8(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
network
low
low
none
August 19, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76395
First tracked: August 19, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 85%