User Data Access Vulnerability in Splunk AI Toolkit from Splunk
CVE-2026-76397
8.1HIGH
What is CVE-2026-76397?
In versions of the Splunk AI Toolkit prior to 6.0.0, users with the 'power' role are able to access and delete sensitive data from the experiment history. This exposure occurs because the toolkit fails to maintain the intended boundaries of the experiment scope, allowing unauthorized manipulation of data associated with other users. This vulnerability can lead to significant privacy and security concerns, particularly in collaborative environments where data integrity is paramount.
Affected Version(s)
Splunk AI Toolkit 5.7 < 6.0.0