CVE-2026-76398
Beschrijving NL
In Splunk AI Toolkit-versies onder 6.0.1 kan een gebruiker die niet de "admin" of "power" Splunk-rollen heeft, de experimentgeschiedenis van een andere gebruiker zonder toestemming verwijderen via de Representational State Transfer (REST) API. De kwetsbaarheid is mogelijk omdat Splunk AI Toolkit de experimentgeschiedenis verwijdert voordat het verifieert dat de gebruiker het bijbehorende experiment kan verwijderen. Zie voor meer informatie Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in de Splunk-documentatie.
Origineel (Engels) tonen
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. For more information see Experiment Assistants (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/use-ai-toolkit/5.6.4/experiment-assistants) in the Splunk documentation.