Authorization Flaw in Splunk AI Toolkit Exposing Configuration Data
CVE-2026-76394

8.3HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76394?

In affected versions of the Splunk AI Toolkit, a vulnerability exists that allows low-privileged users—without admin or power roles—to perform unauthorized actions. Such actions include starting, stopping, and configuring containers, as well as reading and modifying sensitive connection and configuration data via the REST API. This authorization gap arises from the lack of proper authorization checks enforced by multiple REST API handlers. Users must promptly assess their system configurations to prevent potential misuse.

Affected Version(s)

Splunk AI Toolkit 5.7 < 6.0.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.