No advisories yet.
Solution
Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.
Workaround
Turn off or remove the Splunk AI Toolkit app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0808 |
|
Wed, 19 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Splunk
Splunk splunk Ai Toolkit |
|
| Vendors & Products |
Splunk
Splunk splunk Ai Toolkit |
Wed, 19 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation. | |
| Title | Improper Access Control during Experiment History Deletion through the REST API in Splunk AI Toolkit | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-08-19T21:35:13.913Z
Reserved: 2026-08-19T12:02:03.632Z
Link: CVE-2026-76398
No data.
Status : Received
Published: 2026-08-19T22:17:26.400
Modified: 2026-08-19T22:17:26.400
Link: CVE-2026-76398
No data.
OpenCVE Enrichment
Updated: 2026-08-19T23:30:16Z