Executive brief
Splunk AI Toolkit is an extension that enables users to build and manage machine learning experiments within Splunk. A flaw in the REST API allows unprivileged users to delete experiment history records belonging to other users without authorization. This could lead to loss of audit trails, disruption of ML workflows, and unauthorized data destruction.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the experiment history deletion endpoint of Splunk AI Toolkit's REST API. The root cause is that the application deletes experiment history before verifying the requesting user holds the required "admin" or "power" roles. An authenticated user without these roles can invoke the DELETE operation on another user's experiment history through a direct REST API call, achieving unauthorized data destruction. The vulnerability is fixed in versions 6.0.1 (for 6.0 branch) and 6.0.0 (for 5.7 branch).
Affected products
- Splunk AI Toolkit 6.0 below 6.0.1, 5.7 below 6.0.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: advisory: Splunk advisory SVD-2026-0808