Executive brief
Splunk AI Toolkit is a machine learning and analytics tool that manages connections to container services. An unprivileged user can obtain hard-coded or predictable default credentials for these connected container services, potentially leading to unauthorized access and lateral movement within the container infrastructure.
Technical details
This vulnerability (CVE-2026-76392) stems from the use of hard-coded or predictable default credentials when Splunk AI Toolkit generates or stores credentials for connected container services. The vulnerability resides in the Connections tab functionality. An attacker without "admin" or "power" Splunk roles can discover these credentials through the UI or REST API, potentially gaining unauthorized access to backend container services. The vulnerability requires network access to the Splunk instance and authentication as a non-privileged Splunk user. Patched in versions 6.0.0 and later (6.0.1 for the 6.0 branch).
Affected products
- Splunk AI Toolkit Below 6.0.0 (5.7.x and earlier), Below 6.0.1 (6.0.x)
Timeline
- 2026-08-19: disclosed