AUGUST 23, 2026
Live Feed
Back to database
Case File

CVE-2026-76393

MEDIUM · CVSS 5.9 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

In Splunk AI Toolkit versions prior to 6.0.0, a race condition allows users with model upload permissions to overwrite models uploaded by others, potentially leading to the inclusion of malicious content in the model lookup entry. This vulnerability can compromise the integrity of machine learning models, making it a concern for organizations utilizing the toolkit for AI applications. Users of affected versions should prioritize updating to mitigate the risk of unauthorized model manipulation.

CVE
CVE-2026-76393
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%

Original NVD Description

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model lookup entry to reference attacker-controlled content. The race condition is possible because Splunk AI Toolkit does not verify that the uploaded content belongs to the request that creates the model lookup entry. For more information see Troubleshoot the Splunk Machine Learning Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/machine-learning-toolkit-user-guide/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)