In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.
References
| Link | Resource |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0808 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-19 22:17
Updated : 2026-08-21 18:56
NVD link : CVE-2026-76397
Mitre link : CVE-2026-76397
CVE.ORG link : CVE-2026-76397
JSON object : View
Products Affected
splunk
- ai_toolkit
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
