Back to Blog
CVE-2026-20266, CVE-2026-20265: Splunk AI Toolkit — Critical RCE, Data Exposure (June 2024)
vulnerabilities

CVE-2026-20266, CVE-2026-20265: Splunk AI Toolkit — Critical RCE, Data Exposure (June 2024)

breachwire TeamJun 18, 20262 min read

CVE-2026-20266, CVE-2026-20265 — Splunk AI Toolkit

Two critical vulnerabilities, CVE-2026-20266 (OS command injection, CVSS 9.1) and CVE-2026-20265 (insecure default domain allowlist), have been disclosed in Splunk AI Toolkit. These flaws allow remote attackers to execute arbitrary commands on the host or exfiltrate sensitive data. No active exploitation has been reported, but immediate action is required.

Attack Vector

CVE-2026-20266 enables attackers to inject and execute arbitrary operating system commands via crafted inputs to the AI Toolkit, potentially leading to full host compromise. CVE-2026-20265 exposes organizations to data exfiltration by allowing untrusted domains through an insecure default allowlist. Exploitation requires network access to the vulnerable Splunk AI Toolkit instance. No specific IOCs have been published.

Who Is at Risk

All organizations running Splunk AI Toolkit versions prior to 5.7.4 are at risk. This includes any deployment where the AI Toolkit is exposed to internal or external networks. Splunk is the affected vendor; no other organizations are confirmed impacted at this time.

Patch & Mitigate

  • Patch: Upgrade to Splunk AI Toolkit version 5.7.4 immediately.
  • Workaround: None documented; patching is the only effective mitigation.
  • Detect: Review logs for unusual command execution or outbound connections to untrusted domains originating from the AI Toolkit service.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers can gain entry through exposed AI Toolkit endpoints.
  • TA0005 — Defense Evasion: OS command injection enables evasion of standard security controls.

Source: https://securityonline.info/splunk-ai-toolkit-vulnerabilities

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: