HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-76399

CVSS 8.1v3.1pub. 2026-08-19upd. 2026-08-26

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Splunk Ai Toolkit

    APP
    Splunk
    5.7.0 – 6.0.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-20266CRITICAL9.1PL ✓same product

Command Injection w Splunk AI Toolkit — wykonanie poleceń OS przez administratora

CVE-2026-76395HIGH8.8same product

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary co...

CVE-2026-76394HIGH8.3same product

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splu...

CVE-2026-76391HIGH8.3same product

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could ...

CVE-2026-76398MEDIUM4.3same product

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could ...