CVE-2026-76394: In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles c
Summary
Splunk AI Toolkit versions before 6.0.0 have a security flaw where users without admin permissions can control containers and access sensitive data through the REST API (a method for software to communicate over the internet). This happens because the API doesn't properly check whether users have permission to perform these actions.
Solution / Mitigation
Upgrade to Splunk AI Toolkit version 6.0.0 or later.
Vulnerability Details
8.3(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
network
low
low
none
August 19, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76394
First tracked: August 19, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 85%