Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-76399 is a high-severity vulnerability in Splunk AI Toolkit versions 6.0 and 6.0.0, where users with the "power" Splunk role can modify scheduled searches provided by the app to execute arbitrary Search Processing Language (SPL) queries with the permissions of the search owner. This flaw allows unauthorized access to sensitive data and can compromise system integrity. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:14 UTC Added: 08/19/2026, 21:38:41 UTC |
CVE-2026-76398 is a medium severity vulnerability in Splunk AI Toolkit versions 6.0 and 6.0.0 prior to 6.0.1. It allows users without admin or power roles to delete another user's experiment history via the REST API due to missing authorization checks before deletion. This flaw arises because the toolkit deletes experiment history before verifying user permissions. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:13 UTC Added: 08/19/2026, 21:38:41 UTC |
CVE-2026-76397 affects Splunk AI Toolkit versions before 6.0.0 and allows users with the "power" role to access and delete experiment history data belonging to other users by modifying key values. This occurs because the toolkit does not maintain trusted experiment scope when handling caller-controlled query parameters. The vulnerability has a high severity with a CVSS score of 8.1. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:13 UTC Added: 08/19/2026, 21:38:41 UTC |
CVE-2026-76396 is a high-severity vulnerability in Splunk AI Toolkit versions 5.7 up to but not including 6.0.0. It involves improper access control where a user with the schedule_search capability can cause a scheduled search to load and deserialize a model file via the apply search command. This occurs because the apply search command is not marked as risky, allowing unintended privilege escalation. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:12 UTC Added: 08/19/2026, 21:38:41 UTC |
CVE-2026-76395 is a high-severity vulnerability in Splunk AI Toolkit versions 5.7 up to but not including 6.0.0. It allows users with the 'power' Splunk role to execute arbitrary code on the Splunk server by loading a specially crafted model file containing malicious sparse matrix data. This occurs because the model codec deserializes untrusted data without properly verifying or guarding against embedded pickle content. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:12 UTC Added: 08/19/2026, 21:38:40 UTC |
CVE-2026-76394 is a high-severity vulnerability in Splunk AI Toolkit versions 5.7 up to but not including 6.0.0. It allows low-privileged users without admin or power roles to start, stop, and configure containers and read or modify connection and configuration data via the REST API due to missing authorization checks. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:11 UTC Added: 08/19/2026, 21:38:40 UTC |
A race condition vulnerability exists in Splunk AI Toolkit versions 5.7 up to but not including 6.0.0. This flaw allows a user who can upload models to overwrite a model being uploaded by another user by sending concurrent upload requests with the same model name. The vulnerability arises because the toolkit does not verify that the uploaded content corresponds to the request creating the model lookup entry, potentially causing the lookup to reference attacker-controlled content. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:10 UTC Added: 08/19/2026, 21:38:40 UTC |
CVE-2026-76392 is a medium severity vulnerability in Splunk AI Toolkit versions 5.7 and all versions from 5.7 up to but not including 6.0.0. It involves the use of hard-coded or predictable credentials for connected container services, which can be accessed by users without admin or power roles. This issue arises because the toolkit generates or stores credentials using default or predictable values, potentially allowing unauthorized access to these services. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:10 UTC Added: 08/19/2026, 21:38:40 UTC |
CVE-2026-76391 is a high-severity vulnerability in Splunk AI Toolkit versions 5.7 up to but not including 6.0.0. It allows users without admin or power roles to execute searches with system-level privileges, access all relevant data, and manipulate or delete other users' search jobs via the Agent Run History feature. This occurs because the software improperly replaces the user session key with a system authentication token during search operations, bypassing intended access controls. Join the discussion | CVE Database V5 | 08/19/2026, 21:35:09 UTC Added: 08/19/2026, 21:38:40 UTC |
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation. Join the discussion | CVE Database V5 | 06/17/2026, 17:07:24 UTC Added: 06/17/2026, 17:35:20 UTC |
Showing 1 to 10 of 12 results