Skip to content
Critical Vulnerabilities Discovered in Splunk AI Toolkit

Critical Vulnerabilities Discovered in Splunk AI Toolkit

First seen 18 Jun 2026, 14:43 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 19, 2026 at 14:07 UTC
  • •CVE-2026-20265 allows low-privileged users to exfiltrate data via HTTP requests.
  • •CVE-2026-20264 enables admin users to execute arbitrary OS commands on the host.
  • •Splunk recommends upgrading to version 5.7.4 or uninstalling the toolkit immediately.

Two significant vulnerabilities have been identified in the Splunk AI Toolkit versions below 5.7.4. The first, CVE-2026-20265, allows low-privileged users to exfiltrate data by making unauthorized HTTP requests to attacker-controlled servers due to an insecure default domain allowlist. The second vulnerability, identified as CVE-2026-20264, permits admin users to execute arbitrary OS commands on the host system due to unsafe shell execution patterns. Both vulnerabilities require immediate attention, with a recommendation to upgrade to version 5.7.4 or uninstall the toolkit. Splunk has rated the first vulnerability as Medium (4.3) and the second as Critical (9.1). Organizations using the affected versions are at risk of data breaches and system compromise. Security teams are advised to implement the necessary configuration changes or remove the toolkit entirely.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 108d ago How this analysis works

Timeline

2026-06-17
CVE-2026-20265 published
Splunk disclosed a vulnerability allowing low-privileged users to make unauthorized HTTP requests, risking data exfiltration.
advisory.splunk.com
2026-06-17
CVE-2026-20264 published
Splunk announced a critical vulnerability that allows admin users to execute arbitrary OS commands on the host system.
advisory.splunk.com
2026-06-18
Splunk issues advisory for vulnerabilities
Splunk advises users to upgrade to version 5.7.4 or uninstall the AI Toolkit due to critical vulnerabilities.
advisory.splunk.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-20265 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed