CVE-2026-76398

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:splunk:ai_toolkit:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-19 22:17

Updated : 2026-08-24 19:24


NVD link : CVE-2026-76398

Mitre link : CVE-2026-76398

CVE.ORG link : CVE-2026-76398


JSON object : View

Products Affected

splunk

  • ai_toolkit
CWE
CWE-862

Missing Authorization