Skip to content
Threat Feed
high advisory

Authorization Bypass in Splunk AI Toolkit

Splunk AI Toolkit versions prior to 6.0.0 are vulnerable to an authorization bypass where low-privileged users can perform unauthorized administrative actions via the REST API.

CVE search metadata

CVE search record: CVE-2026-76394. Severity: high. CVSS: 8.3. KEV: no. Product: Splunk AI Toolkit. Brief: Authorization Bypass in Splunk AI Toolkit. Brief link: https://feed.craftedsignal.io/briefs/2026-08-splunk-ai-toolkit-auth-bypass/

Splunk AI Toolkit versions below 6.0.0 contain a critical authorization vulnerability. Multiple REST API handlers within the toolkit fail to perform necessary authorization checks, allowing authenticated users lacking 'admin' or 'power' role privileges to interact with sensitive toolkit functions. An attacker can leverage this flaw to start, stop, and configure containers managed by the AI Toolkit, as well as read or modify sensitive connection and configuration data. This vulnerability represents a significant risk for environments where untrusted or low-privileged users have access to the Splunk interface, as it enables unauthorized administrative control over the machine learning infrastructure. Defenders should prioritize upgrading to version 6.0.0 or later to ensure proper role-based access control is enforced on all API endpoints.

Impact

The vulnerability allows unauthorized users to manipulate the machine learning environment, leading to potential data exposure, service disruption via container management, or the alteration of sensitive configuration settings. Any enterprise environment utilizing versions of the Splunk AI Toolkit earlier than 6.0.0 is affected and at risk of internal privilege escalation.

Recommendation

  • Upgrade the Splunk AI Toolkit to version 6.0.0 or higher to remediate CVE-2026-76394.
  • Review Splunk audit logs to identify unusual API activity from users who do not hold 'admin' or 'power' roles, specifically focusing on requests targeting endpoints associated with the AI Toolkit container management and configuration functions.
  • Audit current user roles within the Splunk environment to ensure compliance with the principle of least privilege while the upgrade process is underway.

Immediate actions

Upgrade Splunk AI Toolkit to version 6.0.0

IT Operations 72h

Threat Hunt

REST API calls to AI Toolkit endpoints by low-privileged users

T1068 medium medium confidence hunt now

Data: Splunk internal access logs