Splunk · Splunk Ai Toolkit · CVE-2026-20238
**Name of the Vulnerable Software and Affected Versions**
Splunk AI Toolkit versions prior to 5.7.3
**Description**
A low-privileged user without `admin` or `power` roles can access confidential data restricted by `srchFilter` configurations in custom roles. This occurs because the application includes an `authorize.conf` file with a `srchFilter` entry that modifies the built-in `user` role. Since the Splunk platform uses the `OR` Search Processing Language (SPL) operator to combine inherited search filters, the injected filter overrides more restrictive filters applied to child roles.
**Recommendations**
Update Splunk AI Toolkit to version 5.7.3 or later.