Splunk AI Toolkit <6.0.0: 'Power' Role Deletes All Experiment Data
CVE-2026-76397 Published on August 19, 2026

Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.

NVD

Weakness Type

What is an Insecure Direct Object Reference / IDOR Vulnerability?

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

CVE-2026-76397 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.


Products Associated with CVE-2026-76397

Want to know whenever a new CVE is published for Splunk? stack.watch will email you.

 

Affected Versions

Splunk AI Toolkit: