In Splunk AI Toolkit versions below 6.0.0, improper access control allows a user with the schedule_search capability to cause a scheduled to load and deserialize a model file through the apply command. The apply command is not marked as risky, enabling this unauthorized access.
Any authenticated user with the schedule_search capability can trigger this vulnerability over the network to execute arbitrary code by deserializing a malicious model file through the apply command.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Patch is available. See
Upgrade Splunk AI Toolkit to version 6.0.0 or later. Restrict the schedule_search capability to trusted users only. Review and audit scheduled searches for suspicious model file references or apply command usage.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD published the first details for CVE-2026-76396
Feedly found the first article mentioning CVE-2026-76396 . See article
A CVSS base score of 7.5 has been assigned.
GitHub Advisories released a security advisory .
[GHSA-7f6r-w4cf-54v3] In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the sch
Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
Splunk Fixes Critical MCP Server RCE and Multiple AI Toolkit Vulnerabilities
Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps
Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps
Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
