Executive brief
Splunk AI Toolkit is a machine learning add-on used to build and apply predictive models within Splunk Enterprise. A vulnerability allows users with the schedule_search capability to load and execute arbitrary model files through scheduled searches, bypassing intended access controls. An attacker with scheduling privileges could exploit this to run malicious code or access sensitive data.
Technical details
The vulnerability is an improper access control issue (CWE-269) in Splunk AI Toolkit versions below 6.0.0 and 6.0.1. The apply search command, which deserializes and loads model files, is not marked as risky, allowing users with the schedule_search capability to invoke it in scheduled searches without proper authorization checks. An authenticated user with schedule_search privileges can craft a scheduled search that loads a malicious or unauthorized model file, achieving remote code execution or data exfiltration. The issue has been patched in versions 6.0.0 (for base 5.7) and 6.0.1 (for base 6.0).
Affected products
- Splunk AI Toolkit below 6.0.0 and 6.0.1
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in versions 6.0.0 (base 5.7) and 6.0.1 (base 6.0)