Splunk / AI Toolkit
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-76399 | Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit | HIGH | 8.1 | Aug 19, 2026 |
| CVE-2026-76398 | Improper Access Control during Experiment History Deletion through the REST API in Splunk AI Toolkit | MEDIUM | 4.3 | Aug 19, 2026 |
| CVE-2026-76397 | Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit | HIGH | 8.1 | Aug 19, 2026 |
| CVE-2026-76396 | Improper Access Control through Scheduled Searches in Splunk AI Toolkit | HIGH | 7.5 | Aug 19, 2026 |
| CVE-2026-76395 | Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI Toolkit | HIGH | 8.8 | Aug 19, 2026 |
| CVE-2026-76394 | Missing Authorization in Container and Connection Management through the REST API in Splunk AI Toolkit | HIGH | 8.3 | Aug 19, 2026 |
| CVE-2026-76393 | Race Condition during Model Upload through the REST API in Splunk AI Toolkit | MEDIUM | 5.9 | Aug 19, 2026 |
| CVE-2026-76392 | Use of Hard-coded Credentials in Container Connections in Splunk AI Toolkit | MEDIUM | 5.4 | Aug 19, 2026 |
| CVE-2026-76391 | Improper Privilege Management through Agent Run History in Splunk AI Toolkit | HIGH | 8.3 | Aug 19, 2026 |
| CVE-2026-20266 | OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit | CRITICAL | 9.1 | Jun 17, 2026 |
| CVE-2026-20265 | Insecure Default Domain Allowlist in Splunk AI Toolkit | MEDIUM | 4.3 | Jun 17, 2026 |
| CVE-2026-20238 | Improper Access Control through Role Inheritance in Splunk AI Toolkit app | MEDIUM | 6.5 | May 20, 2026 |
Showing 1 to 12 of 12 CVEs