Skip to content
Threat Feed
high advisory

Privilege Escalation in Splunk AI Toolkit via Agent Run History

A privilege escalation vulnerability in Splunk AI Toolkit versions prior to 6.0.0 allows non-privileged users to execute searches with system-level permissions by exploiting an insecure session token replacement mechanism in the Agent Run History handler.

CVE search metadata

CVE search record: CVE-2026-76391. Severity: high. CVSS: 8.3. KEV: no. Product: AI Toolkit (< 6.0.0), AI Toolkit. Brief: Privilege Escalation in Splunk AI Toolkit via Agent Run History. Brief link: https://feed.craftedsignal.io/briefs/2026-08-splunk-ai-toolkit-privesc/

What's new

  • 1. added coverage for AI Toolkit Aug 19, 22:44 via nvd

Splunk AI Toolkit versions below 6.0.0 contain a privilege escalation vulnerability (CVE-2026-76391) that allows users without administrative or power user roles to execute searches with system-level privileges. The issue stems from the Agent Run History handler, which incorrectly replaces the user's session key with a system authentication token before initiating search operations. This flaw permits unauthorized users to access restricted data, modify system integrity, and manage search jobs belonging to other users. Defenders should identify instances of the AI Toolkit within their environment and upgrade to version 6.0.0 or higher to remediate the insecure authentication handling.

Impact

Successful exploitation allows a low-privileged user to bypass access controls and perform operations with system-level authorization. This results in unauthorized data exfiltration, the ability to view or delete sensitive search jobs of other users, and potential compromise of system integrity within the Splunk environment.

Recommendation

  • Upgrade all Splunk AI Toolkit installations to version 6.0.0 or higher immediately.
  • Audit logs for the Agent Run History handler to identify searches initiated by users without appropriate administrative privileges.
  • Review permissions for all users assigned to the AI Toolkit to minimize exposure while the patch is being applied.
  • Apply the vendor-recommended security patch documented in the Splunk AI Toolkit release notes for version 6.0.0.

Immediate actions

Upgrade Splunk AI Toolkit to version 6.0.0 or higher

IT Operations 48h