PT-2026-78821 · Splunk · Splunk Ai Toolkit

CVE-2026-76394

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk AI Toolkit versions prior to 6.0.0
Description Low-privileged users without admin or power roles can start, stop, and configure containers, as well as read or modify connection and configuration data. This occurs because multiple handlers in the Representational State Transfer (REST) API do not enforce proper authorization checks.
Recommendations Update to version 6.0.0 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76394

Affected Products

Splunk Ai Toolkit