CVE-2026-76393: In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe
Summary
In Splunk AI Toolkit versions before 6.0.0, a race condition (a flaw where the order of simultaneous operations causes unexpected behavior) allows a user to overwrite a model that another user is uploading by sending a competing upload request with the same model name. This happens because the toolkit does not verify that the uploaded content actually belongs to the request that creates the model lookup entry (a database record linking a model name to its contents), potentially allowing an attacker to inject malicious content.
Solution / Mitigation
Upgrade to Splunk AI Toolkit version 6.0.0 or later.
Vulnerability Details
5.9(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L
network
high
low
required
August 19, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76393
First tracked: August 19, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 85%