Critical Vulnerabilities Discovered in Splunk AI Toolkit

Critical Vulnerabilities Discovered in Splunk AI Toolkit

First seen 18 Jun 2026, 14:43 UTC advisory.splunk.com 75% similarity 78.0

Article Content

Browse articles
ThreatCluster

Two significant vulnerabilities have been identified in the Splunk AI Toolkit versions below 5.7.4. The first, CVE-2026-20265, allows low-privileged users to exfiltrate data by making unauthorized HTTP requests to attacker-controlled servers due to an insecure default domain allowlist. The second vulnerability, identified as CVE-2026-20264, permits admin users to execute arbitrary OS commands on the host system due to unsafe shell execution patterns. Both vulnerabilities require immediate attention, with a recommendation to upgrade to version 5.7.4 or uninstall the toolkit. Splunk has rated the first vulnerability as Medium (4.3) and the second as Critical (9.1). Organizations using the affected versions are at risk of data breaches and system compromise. Security teams are advised to implement the necessary configuration changes or remove the toolkit entirely.

Key Points: • CVE-2026-20265 allows low-privileged users to exfiltrate data via HTTP requests. • CVE-2026-20264 enables admin users to execute arbitrary OS commands on the host. • Splunk recommends upgrading to version 5.7.4 or uninstalling the toolkit immediately.

ThreatCluster AI How this analysis works

Timeline

2026-06-17
CVE-2026-20265 published
Splunk disclosed a vulnerability allowing low-privileged users to make unauthorized HTTP requests, risking data exfiltration.
advisory.splunk.com
2026-06-17
CVE-2026-20264 published
Splunk announced a critical vulnerability that allows admin users to execute arbitrary OS commands on the host system.
advisory.splunk.com
2026-06-18
Splunk issues advisory for vulnerabilities
Splunk advises users to upgrade to version 5.7.4 or uninstall the AI Toolkit due to critical vulnerabilities.
advisory.splunk.com

Community

Browse all →

Tracked Entities in This Story