CVE-2026-76392
Last modified
CVE-2026-76392 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores credentials for connected container services using predictable or hard-coded default values. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores credentials for connected container services using predictable or hard-coded default values. For more information see Connections tab in the AI Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.7.2/ai-toolkit-commands-macros-and-visualizations/connections-tab-in-the-ai-toolkit) in the Splunk documentation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Ai Toolkit | >= 5.7.0, < 6.0.0 |
References
- https://advisory.splunk.com/advisories/SVD-2026-0808Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-76392?
How severe is CVE-2026-76392?
How do I fix CVE-2026-76392?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76387In Splunk Enterprise Security versions below 8.6.1, a user w…8.1
- CVE-2026-76388In Splunk Enterprise Security versions below 8.6.1, a user w…8.1
- CVE-2026-76389In Cisco Talos Intelligence for Enterprise Security Cloud ve…8.8
- CVE-2026-7639Software installed and run as a non-privileged user may cond…7.8
- CVE-2026-76390In Cisco Talos Intelligence for Enterprise Security Cloud ve…5.3
- CVE-2026-76391In Splunk AI Toolkit versions below 6.0.0, a user who does n…8.3
- CVE-2026-76393In Splunk AI Toolkit versions below 6.0.0, a user who can up…5.9
- CVE-2026-76394In Splunk AI Toolkit versions below 6.0.0, a low-privileged …8.3
- CVE-2026-76395In Splunk AI Toolkit versions below 6.0.0, a user who holds …8.8
- CVE-2026-76396In Splunk AI Toolkit versions below 6.0.0, a user that holds…7.5
- CVE-2026-76397In Splunk AI Toolkit versions below 6.0.0, a user who holds …8.1
- CVE-2026-76398In Splunk AI Toolkit versions below 6.0.1, a user who does n…4.3
Are you affected by CVE-2026-76392?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
