CVE-2026-76394: In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and...
Added to the CISA Known Exploited Vulnerabilities catalog on 19 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 8.3.
In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorizatio...
Required action: Review and patch if applicable to your AI infrastructure.