PatchSiren cyber security CVE debrief
CVE-2026-76391 Splunk CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:25.487Z and has not been modified since then. This vulnerability affects Splunk AI Toolkit versions below 6.0.0, allowing users without 'admin' or 'power' roles to run searches with system-level privileges due to improper privilege management. The issue arises from the Agent Run History handler replacing the calling user session key with a system authentication token before performing search operations.
- Vendor
- Splunk
- Product
- Splunk AI Toolkit
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Organizations using Splunk AI Toolkit versions below 6.0.0, administrators and users of Splunk AI Toolkit, security teams monitoring system-level privileges and search operations, and operators responsible for maintaining system integrity and data access controls. These stakeholders should be aware of the potential risks and take necessary precautions to mitigate them. Additionally, vulnerability management teams and security teams should review and adjust user roles and permissions to prevent exploitation. IT teams responsible for system updates and patches should prioritize upgrading to version 6.0.0 or later. Asset owners and operators should also be informed about the potential impact on their systems and take appropriate measures to protect them. Furthermore, incident response teams should be prepared to respond to potential security incidents related to this vulnerability. Compliance and regulatory teams may also need to be involved to ensure that the necessary controls are in place to meet regulatory requirements. Lastly, developers and engineers working on Splunk AI Toolkit should be aware of the vulnerability and consider its implications when designing and implementing new features or updates. They should also review the code and ensure that proper privilege management is implemented to prevent similar vulnerabilities in the future. The scope of impact may vary depending on the specific use case and deployment of Splunk AI Toolkit within an organization, so a thorough review of the affected systems and potential exposure is necessary to determine the full extent of the risk. This may involve coordination with various teams, including IT, security, compliance, and development, to ensure a comprehensive understanding of the vulnerability and its potential impact. By taking a proactive and multi-faceted approach, organizations can minimize the risks associated with this vulnerability and protect their systems and data from potential exploitation. The vulnerability management process should include verifying the affected systems, assessing the risk, and implementing controls to mitigate the vulnerability. This may involve applying patches, updating user -
Technical summary
The Splunk AI Toolkit versions below 6.0.0 contain a vulnerability that allows users without 'admin' or 'power' roles to run searches with system-level privileges. This improper privilege management issue occurs because the Agent Run History handler replaces the calling user session key with a system authentication token before performing search operations, potentially allowing access to all relevant data, affecting system integrity, and enabling reading or deleting search jobs belonging to other users.
Defensive priority
Organizations using Splunk AI Toolkit versions below 6.0.0 should prioritize immediate upgrades or compensating controls to mitigate improper privilege management risks.
Recommended defensive actions
- Upgrade Splunk AI Toolkit to version 6.0.0 or later
- Implement compensating controls to restrict search operations
- Monitor system-level privileges and search jobs
- Review and adjust user roles and permissions
- Apply vendor-recommended mitigations
Evidence notes
The CVE description indicates that in Splunk AI Toolkit versions below 6.0.0, users without 'admin' or 'power' roles could run searches with system-level privileges. The issue arises from the Agent Run History handler replacing the calling user session key with a system authentication token before performing search operations. Official records from NVD and CVE.org confirm this vulnerability.
Official resources
-
CVE-2026-76391 CVE record
CVE.org
-
CVE-2026-76391 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:25.487Z and has not been modified since then.