Executive brief
Splunk AI Toolkit versions before 6.0.0 contain an access control flaw that allows users with the "power" role to view and delete experiment history data belonging to other users. This bypasses the intended data isolation and could result in unauthorized data destruction, loss of audit trails, and disruption of machine learning workflows across the organization.
Technical details
The vulnerability is an improper access control flaw (CWE-639) in the experiment history REST API endpoint. The root cause is that Splunk AI Toolkit fails to preserve the trusted experiment scope when processing caller-controlled query values before accessing restricted history data. An attacker with the "power" Splunk role can craft malicious requests to the REST API to access and delete experiment history records associated with other users. No special preconditions beyond holding the "power" role are required. The fix is available in version 6.0.0 for the 5.7 branch and version 6.0.1 for the 6.0 branch.
Affected products
- Splunk AI Toolkit below 6.0.0
Timeline
- 2026-08-19: disclosed