Description
In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit (https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-ai-toolkit/5.7.3/troubleshooting-the-ai-toolkit/troubleshoot-the-ai-toolkit) in the Splunk documentation.
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a user elected to the schedule_search capability to indirectly load and deserialize an external model file when a scheduled search is executed, bypassing the security controls that normally guard the apply search command. This improper access control could expose sensitive model data, lead to unauthorized use of the AI Toolkit, or allow arbitrary command execution within the Splunk environment. The weakness is classified as CWE‑269, indicating a weakness in privilege definition.

Affected Systems

Splunk AI Toolkit deployed in versions prior to 6.0.0 is affected. Any installation of the Splunk AI Toolkit that may be configured for scheduled searches, including the standard Splunk AI Toolkit app and any custom add‑ons reliant on AI Toolkit commands, is subject to this issue. The problem is vendor‑specific and does not affect other Splunk applications unless they explicitly depend on AI Toolkit components.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability presents a medium‑to‑high severity. EPSS information is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is an internal user who possesses role‑based authority to schedule searches, as this capability is required to trigger the deserialization. External exploitation is constrained by the need for authenticated access with the schedule_search permission.

Generated by OpenCVE AI on August 20, 2026 at 07:55 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the Splunk AI Toolkit app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: turning off Splunk AI Toolkit turns off AI Toolkit Search Processing Language (SPL) commands and model operations. Splunk App for Data Science and Deep Learning and custom search commands that depend on AI Toolkit models or APIs might stop functioning. Unrelated Splunk custom search commands are not affected. For more information see [Troubleshoot the Splunk Machine Learning Toolkit](https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) and [DSDL install/version dependencies](https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/splunk-app-for-data-science-and-deep-learning/5.1/install-and-configure-the-splunk-app-for-data-science-and-deep-learning/install-or-upgrade-the-splunk-app-for-data-science-and-deep-learning) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade the Splunk AI Toolkit to version 6.0.0 or later to eliminate the missing risk flag on the apply search command.
  • If an upgrade cannot be performed immediately, disable or remove the Splunk AI Toolkit application while carefully weighing the impact on AI and machine‑learning workflows; note that AI Toolkit SPL commands will cease functioning.
  • Audit role assignments and restrict the schedule_search capability to only trusted administrators, ensuring that routine operators cannot exploit the flaw.

Generated by OpenCVE AI on August 20, 2026 at 07:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk ai Toolkit
CPEs cpe:2.3:a:splunk:ai_toolkit:*:*:*:*:*:*:*:*
Vendors & Products Splunk ai Toolkit

Thu, 20 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Ai Toolkit
Vendors & Products Splunk
Splunk splunk Ai Toolkit

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit (https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-ai-toolkit/5.7.3/troubleshooting-the-ai-toolkit/troubleshoot-the-ai-toolkit) in the Splunk documentation.
Title Improper Access Control through Scheduled Searches in Splunk AI Toolkit
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Ai Toolkit Splunk Ai Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:26:32.441Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76396

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:26.150

Modified: 2026-08-21T18:55:53.703

Link: CVE-2026-76396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management