Impact
The vulnerability allows a user who does not have the “admin” or “power” Splunk roles to delete another user’s experiment history through the REST API. The Toolkit removes experiment history before checking that the user is authorized to delete the experiment, leading to unauthorized data loss. The weakness is an access control flaw (CWE‑862).
Affected Systems
Splunk AI Toolkit versions older than 6.0.1 from the vendor Splunk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. EPSS is not available, and it has not been listed in the CISA KEV catalog, so there is no documented exploitation yet. The likely attack vector is through authenticated REST API calls made by users lacking sufficient roles. An attacker could delete sensitive experiment data, disrupting analytics or compliance efforts.
OpenCVE Enrichment