Splunk has released security fixes for five apps and add-ons, addressing a critical remote code execution flaw in its MCP Server app and a wide range of privilege-management, authorization, deserialization, and data-exposure weaknesses in the Splunk AI Toolkit.
The August 19 security hardening advisory, tracked as SVD-2026-0808, carries a maximum CVSS v3.1 score of 9.1. The most severe issue, CVE-2026-76404, affects Splunk MCP Server app versions earlier than 1.2.1.
The vulnerability allows a user with the Splunk “admin” role to execute arbitrary operating-system commands. Splunk attributed the flaw to insufficient input validation in the credential-management component, which deserializes stored data without ensuring it is the expected type.
Splunk Fixes Multiple Vulnerabilities
Tracked as CWE-502, or deserialization of untrusted data, the issue can enable malicious serialized content to trigger command execution on the host running Splunk.
The vulnerability has a CVSS vector of AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, reflecting that exploitation requires administrative Splunk access but could result in complete compromise.
Splunk AI Toolkit received the largest group of fixes. CVE-2026-76391 and CVE-2026-76394, both rated 8.3, could allow low-privileged users to run searches with system-level privileges or manage containers and connection data via insufficiently protected REST API handlers.
CVE-2026-76395, rated 8.8, permits users with the “power” role to execute arbitrary code by loading a crafted model file containing sparse matrix data with embedded pickle content.
The AI Toolkit flaws also include scheduled-search permission problems, predictable container-service credentials, race conditions during model uploads, and unauthorized access to experiment history.
CVE-2026-76399 allows a “power” user to modify app-provided scheduled searches that run under the search owner’s permissions. This could expose data beyond the user’s intended access level and allow unauthorized changes to Splunk search operations.
Splunk addressed the AI Toolkit vulnerabilities in version 6.0.0 and later, while CVE-2026-76398 and CVE-2026-76399 require version 6.0.1. Administrators should note that disabling the AI Toolkit stops AI Toolkit SPL commands and model operations.
It may also disrupt Splunk Apps for Data Science and Deep Learning deployments, as well as custom search commands that depend on AI Toolkit models and APIs.
| CVE | Affected Product | Vulnerability Type |
|---|---|---|
| CVE-2026-76389 | Cisco Talos Intelligence for Enterprise Security Cloud | SSRF through REST API |
| CVE-2026-76390 | Cisco Talos Intelligence for Enterprise Security Cloud | Information disclosure via unauthenticated OpenAPI specification access |
| CVE-2026-76391 | Splunk AI Toolkit | Improper privilege management through Agent Run History |
| CVE-2026-76392 | Splunk AI Toolkit | Hard-coded or predictable container-service credentials |
| CVE-2026-76393 | Splunk AI Toolkit | Race condition during model upload |
| CVE-2026-76394 | Splunk AI Toolkit | Missing authorization in container and connection REST APIs |
| CVE-2026-76395 | Splunk AI Toolkit | RCE via deserialization of untrusted model data |
| CVE-2026-76396 | Splunk AI Toolkit | Improper access control through scheduled searches |
| CVE-2026-76397 | Splunk AI Toolkit | Improper access control in Experiment History REST API |
| CVE-2026-76398 | Splunk AI Toolkit | Unauthorized deletion of another user’s experiment history |
| CVE-2026-76399 | Splunk AI Toolkit | Incorrect permissions on app-provided scheduled searches |
| CVE-2026-76400 | Splunk Connect for Kafka | DoS through unbounded HTTP Event Collector retry handling |
| CVE-2026-76401 | Splunk Connect for Kafka | Regular expression denial of service through REST API |
| CVE-2026-76402 | Splunk Connect for Kafka | SSRF and HTTP Event Collector credential exposure |
| CVE-2026-76403 | Splunk Connect for Kafka | Improper certificate validation with Kerberos authentication |
| CVE-2026-76404 | Splunk MCP Server app | Critical RCE via unsafe credential-data deserialization |
| CVE-2026-76405 | Splunk On-Call (VictorOps) | API key disclosure through cleartext KV Store storage |
The advisory additionally patches a high-severity server-side request forgery issue in Cisco Talos Intelligence for Enterprise Security Cloud, tracked as CVE-2026-76389.
A user with the get_talos_enrichment capability could send a crafted request to the Talos enrichment REST endpoint, potentially forcing the Splunk instance to contact an attacker-controlled server and expose tokens. The fixed release is Cisco Talos Intelligence version 1.0.3.
Splunk Connect for Kafka version 2.2.7 fixes four issues, including an 8.2-rated SSRF vulnerability that could expose HTTP Event Collector authentication credentials to an attacker-controlled endpoint.
Other Kafka flaws include unbounded event-delivery retries, regular-expression denial-of-service attacks, and improper certificate validation when Kerberos authentication is used.
Organizations should immediately inventory deployed Splunk apps and add-ons, upgrade affected components, and restrict access to Splunk and Kafka Connect REST APIs.
Where prompt patching is not feasible, Splunk recommends disabling or removing vulnerable apps; Kafka operators should also enforce secure HTTP Event Collector transport and configure finite retry limits.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN
