High severity8.1NVD Advisory· Published Aug 19, 2026· Updated Aug 21, 2026
CVE-2026-76397
CVE-2026-76397
Description
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.0.0
Patches
Vulnerability mechanics
References
1- advisory.splunk.com/advisories/SVD-2026-0808nvdVendor Advisory
News mentions
2- Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka AppsCyber Security News · Aug 20, 2026
- Splunk: 25 Vulnerabilities Disclosed, Including Critical RCE and Credential ExposuresVypr Intelligence · Aug 19, 2026