PatchSiren cyber security CVE debrief
CVE-2026-76398 Splunk CVE debrief
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the 'admin' or 'power' Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. This could lead to unauthorized data modifications and potential data loss. To address this, users should update Splunk AI Toolkit to version 6.0.1 or later and restrict access to the REST API for users without admin or power roles. Affected product deployments should be reviewed for exposure, and compensating controls should be considered while remediation is scheduled.
- Vendor
- Splunk
- Product
- Splunk AI Toolkit
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-24
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-24
Who should care
Splunk AI Toolkit users and administrators, especially those with multi-user environments, should be aware of this vulnerability and take necessary actions to prevent unauthorized deletion of experiment history. This includes reviewing user roles, updating the toolkit to version 6.0.1 or later, and implementing additional logging and auditing for experiment history modifications. Security teams should prioritize patching and monitoring to mitigate potential risks associated with this vulnerability.
Technical summary
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the 'admin' or 'power' Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. This could lead to unauthorized data modifications and potential data loss. To address this, users should update Splunk AI Toolkit to version 6.0.1 or later and restrict access to the REST API for users without admin or power roles.
Defensive priority
Medium-priority defensive actions recommended due to potential unauthorized deletion of experiment history by users without admin or power roles.
Recommended defensive actions
- Review and update Splunk AI Toolkit to version 6.0.1 or later
- Restrict access to the REST API for users without admin or power roles
- Monitor for suspicious experiment history deletion activities
- Implement additional logging and auditing for experiment history modifications
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from the NVD and Splunk advisory indicates that in Splunk AI Toolkit versions below 6.0.1, a user without admin or power roles could delete another user's experiment history through the REST API due to insufficient permission checks. The vulnerability allows unauthorized deletion of experiment history, potentially leading to data loss and integrity issues. To verify and mitigate this vulnerability, defenders should review user roles and permissions, ensure that proper authorization checks are in place, and monitor for suspicious experiment history deletion activities.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76398 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76398
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76398 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76398
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-0808
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.