AUGUST 23, 2026
Live Feed
Back to database
Case File

CVE-2026-76397

HIGH · CVSS 8.1 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

In Splunk AI Toolkit versions prior to 6.0.0, users with the "power" role can exploit a vulnerability to access and delete experiment history data, including that of other users, due to inadequate scope preservation during query processing. This poses a significant risk of data loss and unauthorized access to sensitive information. Organizations utilizing the affected versions should prioritize updates to mitigate this high-severity vulnerability.

CVE
CVE-2026-76397
Severity
HIGH
CVSS
8.1
EPSS
0.25%

Original NVD Description

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)