Skip to content
CVE-2026-76399 - Exploits & Severity

CVE-2026-76399 - Exploits & Severity

Feedly • August 20, 2026

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role can modify app-provided scheduled searches to run arbitrary Processing Language (SPL) using the permissions of the owner.

Any authenticated user with the "power" Splunk role can modify scheduled searches to execute arbitrary SPL commands with the permissions of the owner, enabling access to all data that the owner can access and modification of system integrity.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Yes, a patch is available.

Upgrade Splunk AI Toolkit to version 6.0.1 or later. Restrict the "power" role to only trusted administrators who require the ability to manage scheduled searches. Review and audit scheduled searches for any unauthorized modifications.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

NVD published the first details for CVE-2026-76399

A CVSS base score of 8.1 has been assigned.

Feedly found the first article mentioning CVE-2026-76399 . See article

GitHub Advisories released a security advisory .

[GHSA-x8wf-gj49-q42j] In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk r

CVE-2026-76399 - Exploits & Severity - Feedly

Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE

Splunk Fixes Critical MCP Server RCE and Multiple AI Toolkit Vulnerabilities

Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps

Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities