In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.
References
| Link | Resource |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0808 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-19 22:17
Updated : 2026-08-26 20:18
NVD link : CVE-2026-76399
Mitre link : CVE-2026-76399
CVE.ORG link : CVE-2026-76399
JSON object : View
Products Affected
splunk
- ai_toolkit
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
