Cvefeed
Remote Code Execution Vulnerability in Splunk Secure Gateway
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability (CVE-2026-20251) has been identified in Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway, allowing low-privileged users to execute remote code. This vulnerability arises from unsafe deserialization of App Key Value Store data via the 'jsonpickle' Python library. Affected versions include Splunk Enterprise below 10.2.4 and Splunk Cloud Platform below 10.3.2512.12. Splunk has rated this vulnerability as high severity (8.8) and recommends upgrading to the latest versions or removing the Splunk Secure Gateway app. The vulnerability was published on June 10, 2026, and poses a significant risk if not addressed promptly. Organizations are advised to monitor their systems and apply necessary updates or mitigations immediately.
Key Points: • CVE-2026-20251 allows remote code execution for low-privileged users in Splunk products. • Affected versions include Splunk Enterprise below 10.2.4 and Splunk Cloud Platform below 10.3.2512.12. • Splunk rates this vulnerability as high severity (8.8) and recommends immediate action.