Race Condition Vulnerability in Splunk AI Toolkit Affects Model Uploads
CVE-2026-76393

5.9MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76393?

In versions of Splunk AI Toolkit prior to 6.0.0, a concurrency issue allows a user with permission to upload models to overwrite an existing model being uploaded by another user. This is achieved by sending a concurrent upload request using the same model name, leading to a model lookup entry that can reference content controlled by the attacker. The issue arises because the toolkit fails to confirm that the uploaded model content belongs to the authenticated user making the request, exposing it to exploitation. For further information, refer to the Splunk documentation on troubleshooting the Machine Learning Toolkit.

Affected Version(s)

Splunk AI Toolkit 5.7 < 6.0.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shimamine Taihei (島峰 泰平)
.