Splunk AI Toolkit Vulnerabilities: Critical RCE & Data Risks
ID: d01ed837-f391-54e2-bc62-971cee58f136
STIX ID: report--d01ed837-f391-54e2-bc62-971cee58f136
Feed Name: securityonline.info
Splunk AI Toolkit versions prior to 5.7.4 contain two disclosed vulnerabilities: a critical OS command injection (CVE-2026-20266, CVSS 9.1) that allows an admin role to execute arbitrary host commands via unsafe shell execution in the btool configuration helper, and a moderate insecure default domain allowlist (CVE-2026-20265, CVSS 4.3) that can enable low-privileged users to force outbound HTTP requests and potential data exfiltration; patches are available in 5.7.4 and no confirmed exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
