Junglewise Threat Intelligence

CVE-2026-76395: Splunk AI Toolkit RCE through unsafe model deserialization

CVE-2026-76395 · Severity: high · CVSS 8.8 · Published 2026-08-19

Technologies: Splunk AI Toolkit. Vendors: Splunk.

Executive brief

Splunk AI Toolkit is an add-on that enables machine learning capabilities within Splunk, used to build predictive models and automate analytics. Users with administrative privileges ("power" role) can upload and load model files; a flaw in how the toolkit deserializes model data allows uploading a malicious model file to execute arbitrary code on the Splunk server, compromising data, analytics, and system integrity.

Technical details

CVE-2026-76395 is a remote code execution vulnerability caused by unsafe deserialization of untrusted data in the model codec of Splunk AI Toolkit. The vulnerability exists in versions below 6.0.0 (for base 5.7) and below 6.0.1 (for base 6.0). The flaw occurs in the model loading REST API endpoint, where sparse matrix data is deserialized without protection against embedded pickle payloads. An attacker with the "power" Splunk role can craft a model file containing malicious pickle content and upload it via the REST API; upon deserialization, the pickle payload executes arbitrary Python code on the Splunk server. The fix is to upgrade to Splunk AI Toolkit 6.0.0 or later (6.0.1 for base 6.0).

Affected products

  • Splunk AI Toolkit below 6.0.0 (5.7 branch) and below 6.0.1 (6.0 branch)

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: advisory: SVD-2026-0808

References

Related threats