Description
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.
Published: 2026-08-19
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A user with the Splunk "power" role can modify scheduled searches provided by the Splunk AI Toolkit in versions below 6.0.1. By changing these scheduled searches, the user can execute arbitrary Search Processing Language (SPL) commands using the permissions of the search owner. This allows the attacker to query all data accessible to the owner, potentially exposing sensitive information and altering system state. The vulnerability is classified under CWE-732, improper access control for privileged functions.

Affected Systems

The vulnerability affects installations of Splunk AI Toolkit that are older than version 6.0.1. Any instance of the app in which the vendor Splunk provides it is affected. Affected versions include all releases prior to 6.0.1.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS is not available, so the probability of exploitation is currently unknown, but the flaw requires a user with the "power" role, which denotes an elevated privilege level. The vulnerability is not listed in CISA KEV. Because the remote attacker must possess a privileged account, the likely attack vector is internal or through any system that assigns the "power" role.

Generated by OpenCVE AI on August 20, 2026 at 10:05 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the Splunk AI Toolkit app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk AI Toolkit to version 6.0.1 or newer as published by Splunk.
  • If an upgrade cannot be performed immediately, disable or remove the Splunk AI Toolkit app as a temporary workaround.
  • Reevaluate role assignments and ensure that users with the "power" role cannot edit scheduled searches; remove that permission or restrict the role to non‑privileged users.

Generated by OpenCVE AI on August 20, 2026 at 10:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk ai Toolkit
CPEs cpe:2.3:a:splunk:ai_toolkit:*:*:*:*:*:*:*:*
Vendors & Products Splunk ai Toolkit

Wed, 19 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Ai Toolkit
Vendors & Products Splunk
Splunk splunk Ai Toolkit

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.
Title Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Splunk Ai Toolkit Splunk Ai Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T19:51:38.919Z

Reserved: 2026-08-19T12:02:03.632Z

Link: CVE-2026-76399

cve-icon Vulnrichment

Updated: 2026-08-26T19:51:33.488Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:26.523

Modified: 2026-08-26T20:18:01.337

Link: CVE-2026-76399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:15:17Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource