Arbitrary Code Execution Vulnerability in Splunk AI Toolkit
CVE-2026-76395
8.8HIGH
What is CVE-2026-76395?
In affected versions of the Splunk AI Toolkit, specifically those prior to 6.0.0, an exploit occurs whereby users with the 'power' role can load model files containing malicious sparse matrix data. This vulnerability arises from the deserialization process of untrusted data, as the toolkit does not properly protect against harmful embedded pickle content. Attackers could potentially execute arbitrary code on the Splunk server, which poses significant risks to enterprise environments. For detailed guidance, consult the official Splunk documentation on troubleshooting the Machine Learning Toolkit.
Affected Version(s)
Splunk AI Toolkit 5.7 < 6.0.0