Splunk AI Toolkit Vulnerability Allows Arbitrary OS Command Execution
ID: 8873ecb3-399b-5d7d-a532-adfe874ed750
STIX ID: report--8873ecb3-399b-5d7d-a532-adfe874ed750
Feed Name: GBHackers
Splunk disclosed two vulnerabilities in its AI Toolkit affecting versions before 5.7.4: CVE-2026-20266 (CVSS 9.1) is an OS command injection in the btool helper that can let authenticated admin users execute arbitrary OS commands, and CVE-2026-20265 (CVSS 4.3) is an insecure default domain allowlist that enables low-privileged users to trigger outbound HTTP requests. Splunk advises immediate upgrade to 5.7.4 or removal of the AI Toolkit and recommends configuring and enforcing allowed domains to mitigate the issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
