CVE-2026-76393: In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causin...

Added to the CISA Known Exploited Vulnerabilities catalog on 19 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 5.9.

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model lookup entry to reference attacker-controlled content. The race condition is p...

Required action: Review and patch if applicable to your AI infrastructure.