Remote Code Execution Vulnerability in Splunk Secure Gateway

Remote Code Execution Vulnerability in Splunk Secure Gateway

First seen 11 Jun 2026, 01:27 UTC Advisory.SplunkCvefeedwww.cve.org 91% similarity 70.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-20251) has been identified in Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway, allowing low-privileged users to execute remote code. This vulnerability arises from unsafe deserialization of App Key Value Store data via the 'jsonpickle' Python library. Affected versions include Splunk Enterprise below 10.2.4 and Splunk Cloud Platform below 10.3.2512.12. Splunk has rated this vulnerability as high severity (8.8) and recommends upgrading to the latest versions or removing the Splunk Secure Gateway app. The vulnerability was published on June 10, 2026, and poses a significant risk if not addressed promptly. Organizations are advised to monitor their systems and apply necessary updates or mitigations immediately.

Key Points: • CVE-2026-20251 allows remote code execution for low-privileged users in Splunk products. • Affected versions include Splunk Enterprise below 10.2.4 and Splunk Cloud Platform below 10.3.2512.12. • Splunk rates this vulnerability as high severity (8.8) and recommends immediate action.

ThreatCluster AI

Timeline

2026-06-10
CVE-2026-20251 published
Splunk disclosed a remote code execution vulnerability affecting multiple versions of its products.
Advisory.Splunk

Community

Browse all →

Tracked Entities in This Story