Arbitrary Code Execution Vulnerability in Splunk AI Toolkit
CVE-2026-76395

8.8HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76395?

In affected versions of the Splunk AI Toolkit, specifically those prior to 6.0.0, an exploit occurs whereby users with the 'power' role can load model files containing malicious sparse matrix data. This vulnerability arises from the deserialization process of untrusted data, as the toolkit does not properly protect against harmful embedded pickle content. Attackers could potentially execute arbitrary code on the Splunk server, which poses significant risks to enterprise environments. For detailed guidance, consult the official Splunk documentation on troubleshooting the Machine Learning Toolkit.

Affected Version(s)

Splunk AI Toolkit 5.7 < 6.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.