Medium severity5.4NVD Advisory· Published Aug 19, 2026· Updated Aug 26, 2026
CVE-2026-76392
CVE-2026-76392
Description
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores credentials for connected container services using predictable or hard-coded default values. For more information see Connections tab in the AI Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.7.2/ai-toolkit-commands-macros-and-visualizations/connections-tab-in-the-ai-toolkit) in the Splunk documentation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <6.0.0
- Range: <6.0.0
Patches
Vulnerability mechanics
References
1- advisory.splunk.com/advisories/SVD-2026-0808nvdVendor Advisory
News mentions
2- Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka AppsCyber Security News · Aug 20, 2026
- Splunk: 25 Vulnerabilities Disclosed, Including Critical RCE and Credential ExposuresVypr Intelligence · Aug 19, 2026