Impact
The vulnerability allows a user elected to the schedule_search capability to indirectly load and deserialize an external model file when a scheduled search is executed, bypassing the security controls that normally guard the apply search command. This improper access control could expose sensitive model data, lead to unauthorized use of the AI Toolkit, or allow arbitrary command execution within the Splunk environment. The weakness is classified as CWE‑269, indicating a weakness in privilege definition.
Affected Systems
Splunk AI Toolkit deployed in versions prior to 6.0.0 is affected. Any installation of the Splunk AI Toolkit that may be configured for scheduled searches, including the standard Splunk AI Toolkit app and any custom add‑ons reliant on AI Toolkit commands, is subject to this issue. The problem is vendor‑specific and does not affect other Splunk applications unless they explicitly depend on AI Toolkit components.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability presents a medium‑to‑high severity. EPSS information is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is an internal user who possesses role‑based authority to schedule searches, as this capability is required to trigger the deserialization. External exploitation is constrained by the need for authenticated access with the schedule_search permission.
OpenCVE Enrichment