PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76399 Splunk CVE debrief

In Splunk AI Toolkit versions below 6.0.1, a user who holds the 'power' Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner. This could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the 'power' Splunk role permission to modify scheduled searches that run using the permissions of the search owner. Organizations should be aware of this vulnerability and take steps to mitigate it, focusing on users with the 'power' Splunk role and monitoring for unusual search activity.

Vendor
Splunk
Product
Splunk AI Toolkit
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-26
Advisory published
2026-08-19
Advisory updated
2026-08-26

Who should care

Organizations using Splunk AI Toolkit versions below 6.0.1, particularly those with users holding the 'power' Splunk role, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing current search configurations, adjusting permissions for search owners, and implementing additional monitoring for search activity related to the 'power' Splunk role.

Technical summary

In Splunk AI Toolkit versions below 6.0.1, a user who holds the 'power' Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner. This could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the 'power' Splunk role permission to modify scheduled searches that run using the permissions of the search owner. To mitigate, organizations should prioritize patching to version 6.0.1 or later, restrict 'power' Splunk role usage, and monitor for unusual search activity.

Defensive priority

Organizations using Splunk AI Toolkit versions below 6.0.1 should prioritize patching, focusing on users with the 'power' Splunk role, and monitor for unusual search activity.

Recommended defensive actions

  • Patch Splunk AI Toolkit to version 6.0.1 or later
  • Restrict 'power' Splunk role usage to minimize potential impact
  • Monitor scheduled searches for unusual activity
  • Review and adjust permissions for search owners
  • Conduct a thorough review of current search configurations and usage
  • Implement additional monitoring for search activity related to the 'power' Splunk role
  • Verify that all users with the 'power' Splunk role understand the implications of this vulnerability

Evidence notes

The CVE description indicates that in Splunk AI Toolkit versions below 6.0.1, a user with the 'power' Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner. This could allow access to all relevant data and affect system integrity. Evidence is based on the official CVE Program record and NVD vulnerability detail.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76399 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76399

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76399 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76399

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.