Impact
Splunk AI Toolkit versions below 6.0.0 lack proper scope enforcement when processing caller‑controlled query values. A user granted the "power" role can retrieve and delete all experiment history entries, including data belonging to other users. This results in unauthorized disclosure of sensitive information and loss of data integrity.
Affected Systems
The vulnerability affects Splunk's AI Toolkit application. All installations of the app with a version earlier than 6.0.0 are impacted. Users of the "power" role within those environments can exploit the flaw.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting a moderate exploitation risk in the current threat landscape. Exploitation requires the attacker to have access to the REST API and be assigned the "power" role, implying that internal attackers or those who have compromised a privileged account pose the greatest threat. The attack vector is inferred to be via the REST API after authentication, as the flaw arises from improper access control rather than an external remote code execution entry point.
OpenCVE Enrichment