advisory.splunk.com
Critical Vulnerabilities Discovered in Splunk AI Toolkit
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two significant vulnerabilities have been identified in the Splunk AI Toolkit versions below 5.7.4. The first, CVE-2026-20265, allows low-privileged users to exfiltrate data by making unauthorized HTTP requests to attacker-controlled servers due to an insecure default domain allowlist. The second vulnerability, identified as CVE-2026-20264, permits admin users to execute arbitrary OS commands on the host system due to unsafe shell execution patterns. Both vulnerabilities require immediate attention, with a recommendation to upgrade to version 5.7.4 or uninstall the toolkit. Splunk has rated the first vulnerability as Medium (4.3) and the second as Critical (9.1). Organizations using the affected versions are at risk of data breaches and system compromise. Security teams are advised to implement the necessary configuration changes or remove the toolkit entirely.
Key Points: • CVE-2026-20265 allows low-privileged users to exfiltrate data via HTTP requests. • CVE-2026-20264 enables admin users to execute arbitrary OS commands on the host. • Splunk recommends upgrading to version 5.7.4 or uninstalling the toolkit immediately.