Authorization Flaw in Splunk AI Toolkit Exposing Configuration Data
CVE-2026-76394
8.3HIGH
What is CVE-2026-76394?
In affected versions of the Splunk AI Toolkit, a vulnerability exists that allows low-privileged users—without admin or power roles—to perform unauthorized actions. Such actions include starting, stopping, and configuring containers, as well as reading and modifying sensitive connection and configuration data via the REST API. This authorization gap arises from the lack of proper authorization checks enforced by multiple REST API handlers. Users must promptly assess their system configurations to prevent potential misuse.
Affected Version(s)
Splunk AI Toolkit 5.7 < 6.0.0