logo

Splunk AI Toolkit Vulnerability Allows Arbitrary OS Command Execution

ID: 8873ecb3-399b-5d7d-a532-adfe874ed750

STIX ID: report--8873ecb3-399b-5d7d-a532-adfe874ed750

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Divya

...
...

Splunk disclosed two vulnerabilities in its AI Toolkit affecting versions before 5.7.4: CVE-2026-20266 (CVSS 9.1) is an OS command injection in the btool helper that can let authenticated admin users execute arbitrary OS commands, and CVE-2026-20265 (CVSS 4.3) is an insecure default domain allowlist that enables low-privileged users to trigger outbound HTTP requests. Splunk advises immediate upgrade to 5.7.4 or removal of the AI Toolkit and recommends configuring and enforcing allowed domains to mitigate the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.