Description
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege management is possible because the Agent Run History handler replaces the calling user session key with a system authentication token before it performs search operations. For more information see AI Toolkit Agent Launchpad (https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-ai-toolkit/6.0.0/ai-toolkit-connections-containers-and-agents/ai-toolkit-agent-launchpad) in the Splunk documentation.
Published: 2026-08-19
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Splunk AI Toolkit versions before 6.0.0 allow users without admin or power roles to run searches with system-level privileges by invoking Agent Run History, during which the handler substitutes the user’s session key with a system token. This substitution grants access to all relevant data and the ability to read or delete other users’ search jobs, enabling privilege escalation and compromising system integrity.

Affected Systems

The vulnerability affects Splunk AI Toolkit installations where the version is less than 6.0.0, specifically the Splunk AI Toolkit app within the Splunk environment. It is independent of other Splunk components and is present in all affected versions of the app regardless of additional add‑ons.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a moderate exploitation likelihood at this time. Attackers would need authenticated access to a non‑admin user account and would exploit the Agent Run History feature to elevate privileges, access sensitive data, and disrupt other users’ search jobs. The flaw involves system token replacement, making the likely attack vector internal to Splunk’s web interface or API.

Generated by OpenCVE AI on August 20, 2026 at 09:49 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the Splunk AI Toolkit app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: turning off Splunk AI Toolkit turns off AI Toolkit Search Processing Language (SPL) commands and model operations. Splunk App for Data Science and Deep Learning and custom search commands that depend on AI Toolkit models or APIs might stop functioning. Unrelated Splunk custom search commands are not affected. For more information see [Troubleshoot the Splunk Machine Learning Toolkit](https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) and [DSDL install/version dependencies](https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/splunk-app-for-data-science-and-deep-learning/5.1/install-and-configure-the-splunk-app-for-data-science-and-deep-learning/install-or-upgrade-the-splunk-app-for-data-science-and-deep-learning) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk AI Toolkit to the fixed version (6.0.0 or later)
  • If an upgrade is not yet available, turn off or remove the Splunk AI Toolkit app
  • If disabling the app is not feasible, restrict non‑admin users from using Agent Run History by adjusting role permissions

Generated by OpenCVE AI on August 20, 2026 at 09:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:splunk:ai_toolkit:*:*:*:*:*:*:*:*

Wed, 19 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk ai Toolkit
Vendors & Products Splunk
Splunk ai Toolkit

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege management is possible because the Agent Run History handler replaces the calling user session key with a system authentication token before it performs search operations. For more information see AI Toolkit Agent Launchpad (https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-ai-toolkit/6.0.0/ai-toolkit-connections-containers-and-agents/ai-toolkit-agent-launchpad) in the Splunk documentation.
Title Improper Privilege Management through Agent Run History in Splunk AI Toolkit
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Splunk Ai Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:20:41.779Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76391

cve-icon Vulnrichment

Updated: 2026-08-26T15:17:04.970Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-19T22:17:25.487

Modified: 2026-08-26T16:16:41.460

Link: CVE-2026-76391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses