advisory.splunk.com Critical Vulnerabilities Discovered in Splunk AI Toolkit
Article Content
- •CVE-2026-20265 allows low-privileged users to exfiltrate data via HTTP requests.
- •CVE-2026-20264 enables admin users to execute arbitrary OS commands on the host.
- •Splunk recommends upgrading to version 5.7.4 or uninstalling the toolkit immediately.
Two significant vulnerabilities have been identified in the Splunk AI Toolkit versions below 5.7.4. The first, CVE-2026-20265, allows low-privileged users to exfiltrate data by making unauthorized HTTP requests to attacker-controlled servers due to an insecure default domain allowlist. The second vulnerability, identified as CVE-2026-20264, permits admin users to execute arbitrary OS commands on the host system due to unsafe shell execution patterns. Both vulnerabilities require immediate attention, with a recommendation to upgrade to version 5.7.4 or uninstall the toolkit. Splunk has rated the first vulnerability as Medium (4.3) and the second as Critical (9.1). Organizations using the affected versions are at risk of data breaches and system compromise. Security teams are advised to implement the necessary configuration changes or remove the toolkit entirely.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-20265 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…