THE Splunk AI Toolkit has two critical vulnerabilities: CVE-2026-20266, an OS Command Injection issue rated at CVSS 9.1, and CVE-2026-20265, an insecure default domain allowlist rated at CVSS 4.3. Patches are available in version 5.7.4. The OS Command Injection allows attackers to execute arbitrary commands on the host, while the second flaw can lead to data exfiltration. Organizations are urged to update to the latest version immediately to mitigate risks.
Splunk AI Toolkit flaw allows arbitrary command execution
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Splunk patches AI Toolkit OS command injection flaw CVE-2026-20266
securityonline.info
-
Splunk AI Toolkit flaw allows arbitrary command execution
securityonline.info