AUGUST 23, 2026
Live Feed
Back to database
Case File

CVE-2026-76395

HIGH · CVSS 8.8 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Splunk AI Toolkit versions prior to 6.0.0 are vulnerable to arbitrary code execution due to improper deserialization of untrusted sparse matrix data by a model codec, which allows users with the "power" role to exploit this flaw. The impact of this vulnerability is significant, as it could lead to unauthorized access and control over the Splunk server. Organizations using affected versions of the Splunk AI Toolkit should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-76395
Severity
HIGH
CVSS
8.8
EPSS
0.48%

Original NVD Description

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Troubleshoot the Splunk Machine Learning Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/machine-learning-toolkit-user-guide/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)