CVE-2026-76397

Summary

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.

Affected Software

VendorProductVersion RangeStatus
SplunkSplunk AI Toolkit5.7 < 6.0.0affected

Weaknesses

  • CWE-639: The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Workarounds

Turn off or remove the Splunk AI Toolkit app. For more information see Manage app and add-on objects in the Splunk documentation.

References