Executive brief
Splunk AI Toolkit is a machine learning extension for Splunk that allows users to upload and manage predictive models. A race condition in the model upload feature allows an authenticated user to overwrite another user's model by sending concurrent upload requests with the same model name, potentially injecting malicious model content that will be executed during model inference.
Technical details
CVE-2026-76393 is a race condition (CWE-362) in Splunk AI Toolkit's model upload REST API. The vulnerability occurs because the toolkit does not verify that uploaded model content matches the model lookup entry created for the same upload request. An attacker with model upload capability can exploit this by sending concurrent upload requests for the same model name; the resulting model lookup entry may reference attacker-controlled model content if the attacker's upload completes after another user's lookup entry is created but before the legitimate content is associated. Attack vector is network-based, requires authentication and the ability to upload models, and can result in arbitrary model substitution leading to potential code execution during model inference. Patches are available in Splunk AI Toolkit versions 6.0.0 and 6.0.1 or later.
Affected products
- Splunk AI Toolkit below 6.0.0 (6.x branch) and below 6.0.1 (6.0+ branch)
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fix versions: 6.0.0 and 6.0.1 available