Description
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.
Published: 2026-08-19
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Splunk AI Toolkit versions below 6.0.0 lack proper scope enforcement when processing caller‑controlled query values. A user granted the "power" role can retrieve and delete all experiment history entries, including data belonging to other users. This results in unauthorized disclosure of sensitive information and loss of data integrity.

Affected Systems

The vulnerability affects Splunk's AI Toolkit application. All installations of the app with a version earlier than 6.0.0 are impacted. Users of the "power" role within those environments can exploit the flaw.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting a moderate exploitation risk in the current threat landscape. Exploitation requires the attacker to have access to the REST API and be assigned the "power" role, implying that internal attackers or those who have compromised a privileged account pose the greatest threat. The attack vector is inferred to be via the REST API after authentication, as the flaw arises from improper access control rather than an external remote code execution entry point.

Generated by OpenCVE AI on August 20, 2026 at 09:48 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the Splunk AI Toolkit app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk AI Toolkit to version 6.0.0 or later to apply the vendor‑supplied fix
  • If upgrade cannot be performed immediately, disable or remove the Splunk AI Toolkit app to prevent access
  • Ensure users who hold the "power" role cannot access experiment history until the application is updated
  • Monitor audit logs for unauthorized access or deletion attempts to detect exploitation early

Generated by OpenCVE AI on August 20, 2026 at 09:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk ai Toolkit
CPEs cpe:2.3:a:splunk:ai_toolkit:*:*:*:*:*:*:*:*
Vendors & Products Splunk ai Toolkit

Wed, 19 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Ai Toolkit
Vendors & Products Splunk
Splunk splunk Ai Toolkit

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.
Title Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Splunk Ai Toolkit Splunk Ai Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:26:32.279Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76397

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:26.270

Modified: 2026-08-21T18:56:07.450

Link: CVE-2026-76397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key