PT-2026-78818 · Splunk · Splunk Ai Toolkit

CVE-2026-76391

·

Published

2026-08-19

·

Updated

2026-08-26

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Splunk AI Toolkit versions prior to 6.0.0
Description Improper privilege management in the Agent Run History handler allows users without admin or power roles to execute searches with system-level privileges. This occurs because the handler replaces the calling user session key with a system authentication token during search operations, enabling unauthorized access to all relevant data, compromise of system integrity, and the ability to read or delete search jobs belonging to other users.
Recommendations Update Splunk AI Toolkit to version 6.0.0 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76391

Affected Products

Splunk Ai Toolkit