CVE-2026-76397
Received Received - Intake

Privilege Escalation in Splunk AI Toolkit

Vulnerability report for CVE-2026-76397, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
splunk splunk_ai_toolkit to 6.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In Splunk AI Toolkit versions below 6.0.0, a user with the 'power' role can access and delete experiment history data, including data belonging to other users. This happens because the toolkit does not maintain proper data isolation when processing user-controlled queries.

Impact Analysis

If you use Splunk AI Toolkit versions below 6.0.0, an attacker with the 'power' role could delete or access sensitive experiment data, leading to data loss or unauthorized exposure of information.

Compliance Impact

This vulnerability could violate compliance requirements by allowing unauthorized access or deletion of sensitive data, potentially breaching GDPR or HIPAA if experiment data includes personal or health information.

Mitigation Strategies

Upgrade Splunk AI Toolkit to version 6.0.0 or higher to address the vulnerability. Ensure users with the power role are restricted from accessing or modifying experiment history data. Review and enforce proper access controls for experiment history.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76397. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart