Impact
In Splunk AI Toolkit versions prior to 6.0.0, several REST API handlers failed to perform proper authorization checks. A low‑privileged user who is not a member of the "admin" or "power" roles can therefore start, stop, and configure containers, as well as read and modify connection and configuration data. This allows the attacker to change the execution environment of the toolkit, potentially leading to denial of service or the execution of arbitrary code within the containers. The flaw reflects an inadequate authorization mechanism, as identified by CWE‑862.
Affected Systems
The vulnerability affects the Splunk AI Toolkit app/add‑on for all installations where the version is below 6.0.0. The recommended fix is to upgrade each affected Splunk app or add‑on to the applicable fixed version listed in Product Status, which includes any release 6.0.0 or later of the AI Toolkit.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability, and although no EPSS value is available, the lack of authorization checks suggests a moderate exploitation likelihood for authenticated users. The vulnerability is not listed in the CISA KEV catalog, but its impact on container orchestration and configuration data can be substantial if an attacker gains control. The likely attack vector is through the REST API; an attacker must be authenticated with any non‑admin role, then issue API requests that target the affected endpoints. Given the high severity and the permissive access for low‑privileged users, the risk to affected environments is considered high.
OpenCVE Enrichment