User Data Access Vulnerability in Splunk AI Toolkit from Splunk
CVE-2026-76397

8.1HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76397?

In versions of the Splunk AI Toolkit prior to 6.0.0, users with the 'power' role are able to access and delete sensitive data from the experiment history. This exposure occurs because the toolkit fails to maintain the intended boundaries of the experiment scope, allowing unauthorized manipulation of data associated with other users. This vulnerability can lead to significant privacy and security concerns, particularly in collaborative environments where data integrity is paramount.

Affected Version(s)

Splunk AI Toolkit 5.7 < 6.0.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.