PatchSiren cyber security CVE debrief
CVE-2026-76399 Splunk CVE debrief
In Splunk AI Toolkit versions below 6.0.1, a user who holds the 'power' Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner. This could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the 'power' Splunk role permission to modify scheduled searches that run using the permissions of the search owner. Organizations should be aware of this vulnerability and take steps to mitigate it, focusing on users with the 'power' Splunk role and monitoring for unusual search activity.
- Vendor
- Splunk
- Product
- Splunk AI Toolkit
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-26
Who should care
Organizations using Splunk AI Toolkit versions below 6.0.1, particularly those with users holding the 'power' Splunk role, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing current search configurations, adjusting permissions for search owners, and implementing additional monitoring for search activity related to the 'power' Splunk role.
Technical summary
In Splunk AI Toolkit versions below 6.0.1, a user who holds the 'power' Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner. This could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the 'power' Splunk role permission to modify scheduled searches that run using the permissions of the search owner. To mitigate, organizations should prioritize patching to version 6.0.1 or later, restrict 'power' Splunk role usage, and monitor for unusual search activity.
Defensive priority
Organizations using Splunk AI Toolkit versions below 6.0.1 should prioritize patching, focusing on users with the 'power' Splunk role, and monitor for unusual search activity.
Recommended defensive actions
- Patch Splunk AI Toolkit to version 6.0.1 or later
- Restrict 'power' Splunk role usage to minimize potential impact
- Monitor scheduled searches for unusual activity
- Review and adjust permissions for search owners
- Conduct a thorough review of current search configurations and usage
- Implement additional monitoring for search activity related to the 'power' Splunk role
- Verify that all users with the 'power' Splunk role understand the implications of this vulnerability
Evidence notes
The CVE description indicates that in Splunk AI Toolkit versions below 6.0.1, a user with the 'power' Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner. This could allow access to all relevant data and affect system integrity. Evidence is based on the official CVE Program record and NVD vulnerability detail.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76399 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76399
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76399 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76399
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-0808
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.