MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2026-76398

CVSS 4.3v3.1pub. 2026-08-19upd. 2026-08-24

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  • Splunk Ai Toolkit

    APP
    Splunk
    5.7.0 – 6.0.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-20266CRITICAL9.1PL ✓same product

Command Injection w Splunk AI Toolkit — wykonanie poleceń OS przez administratora

CVE-2026-76399HIGH8.1same product

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided ...

CVE-2026-76394HIGH8.3same product

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splu...

CVE-2026-76391HIGH8.3same product

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could ...

CVE-2026-76395HIGH8.8same product

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary co...