Race Condition Vulnerability in Splunk AI Toolkit Affects Model Uploads
CVE-2026-76393
5.9MEDIUM
What is CVE-2026-76393?
In versions of Splunk AI Toolkit prior to 6.0.0, a concurrency issue allows a user with permission to upload models to overwrite an existing model being uploaded by another user. This is achieved by sending a concurrent upload request using the same model name, leading to a model lookup entry that can reference content controlled by the attacker. The issue arises because the toolkit fails to confirm that the uploaded model content belongs to the authenticated user making the request, exposing it to exploitation. For further information, refer to the Splunk documentation on troubleshooting the Machine Learning Toolkit.
Affected Version(s)
Splunk AI Toolkit 5.7 < 6.0.0