CVE-2026-76395: In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. ...

Added to the CISA Known Exploited Vulnerabilities catalog on 19 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 8.8.

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deseria...

Required action: Review and patch if applicable to your AI infrastructure.