PatchSiren cyber security CVE debrief
CVE-2026-76395 Splunk CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:26.023Z and has not been modified since then. This vulnerability affects Splunk AI Toolkit versions below 6.0.0, allowing a user with the 'power' Splunk role to execute arbitrary code by loading a crafted model file. The deserialization of untrusted sparse matrix data is possible due to a lack of safeguards against embedded pickle content in the model codec. The vulnerability has a high CVSS score of 8.8, indicating a high severity level. It is crucial for Splunk administrators and users with the 'power' role to be aware of this vulnerability and take immediate action to mitigate the risk.
- Vendor
- Splunk
- Product
- Splunk AI Toolkit
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Splunk administrators and users with the 'power' role should be aware of this vulnerability and take immediate action to mitigate the risk. Additionally, security teams and IT personnel responsible for monitoring and patching vulnerabilities should prioritize this issue due to its high severity. Asset owners and operators of Splunk AI Toolkit should also be informed to ensure prompt action is taken to secure their environments. Vulnerability management teams should review and update their processes to include this critical vulnerability. Furthermore, incident response teams should be prepared to handle potential exploitation attempts and have plans in place for rapid response and mitigation.
Technical summary
The Splunk AI Toolkit versions below 6.0.0 are vulnerable to arbitrary code execution due to the deserialization of untrusted sparse matrix data. A user with the 'power' Splunk role can load a crafted model file to execute code on the Splunk server. This vulnerability is particularly concerning due to the high CVSS score of 8.8 and the potential for significant impact on Splunk server security. The deserialization process lacks proper safeguards against embedded pickle content, allowing for the execution of arbitrary code.
Defensive priority
High priority due to the high CVSS score of 8.8 and the potential for arbitrary code execution.
Recommended defensive actions
- Inventory and assess Splunk AI Toolkit versions below 6.0.0 for potential vulnerability
- Restrict access to the 'power' Splunk role to minimize potential impact
- Implement compensating controls to monitor and detect suspicious model file loading activities
- Apply the vendor-provided patch or upgrade to version 6.0.0 or later
- Monitor for any suspicious activity related to model file loading and deserialization
Evidence notes
Evidence from the NVD and Splunk advisory indicates that a user with the 'power' Splunk role could execute arbitrary code by loading a crafted model file. The issue is due to the deserialization of untrusted sparse matrix data in the Splunk AI Toolkit. Further review of the Splunk documentation and vendor advisory is recommended to understand the full scope of the vulnerability and potential mitigations. Additionally, defenders should verify the integrity of model files and monitor for suspicious deserialization activities.
Official resources
-
CVE-2026-76395 CVE record
CVE.org
-
CVE-2026-76395 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:26.023Z and has not been modified since then.