Description
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a user who does not have the “admin” or “power” Splunk roles to delete another user’s experiment history through the REST API. The Toolkit removes experiment history before checking that the user is authorized to delete the experiment, leading to unauthorized data loss. The weakness is an access control flaw (CWE‑862).

Affected Systems

Splunk AI Toolkit versions older than 6.0.1 from the vendor Splunk.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. EPSS is not available, and it has not been listed in the CISA KEV catalog, so there is no documented exploitation yet. The likely attack vector is through authenticated REST API calls made by users lacking sufficient roles. An attacker could delete sensitive experiment data, disrupting analytics or compliance efforts.

Generated by OpenCVE AI on August 20, 2026 at 09:47 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the Splunk AI Toolkit app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Apply the official patch by upgrading to Splunk AI Toolkit 6.0.1 or later.
  • If a patch cannot be applied immediately, uninstall or disable the Splunk AI Toolkit app.
  • Configure role‑based access to restrict REST API delete actions to only privileged users, and audit delete requests for unauthorized activity.

Generated by OpenCVE AI on August 20, 2026 at 09:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk ai Toolkit
CPEs cpe:2.3:a:splunk:ai_toolkit:*:*:*:*:*:*:*:*
Vendors & Products Splunk ai Toolkit

Wed, 19 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Ai Toolkit
Vendors & Products Splunk
Splunk splunk Ai Toolkit

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.
Title Improper Access Control during Experiment History Deletion through the REST API in Splunk AI Toolkit
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Splunk Ai Toolkit Splunk Ai Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:26:32.108Z

Reserved: 2026-08-19T12:02:03.632Z

Link: CVE-2026-76398

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:26.400

Modified: 2026-08-24T19:24:02.817

Link: CVE-2026-76398

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses