CVE-2026-76396

Improper Access Control through Scheduled Searches in Splunk AI Toolkit

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.002
14.7th percentile
Discovered by
Not disclosed
Published
Aug 19, 2026
Assigned by cisco

Description

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit (https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-ai-toolkit/5.7.3/troubleshooting-the-ai-toolkit/troubleshoot-the-ai-toolkit) in the Splunk documentation.

Weakness: CWE-269

Affected products

Vendor Product Category Matched by
Cisco Splunk Apps & Add-ons SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Splunk · Splunk AI Toolkit

Credit

Gabriel Nitu, Splunk

Vendor remediation

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.

Something wrong here?