securityonline.info 8/20/2026, 5:21:27 AM · external

Splunk patches AI Toolkit OS command injection flaw CVE-2026-20266

Splunk patches AI Toolkit OS command injection flaw CVE-2026-20266
CyberSIXT Evidence Panel
Primary Source advisory.splunk.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

SPLUNK has patched a critical OS command injection vulnerability in its AI Toolkit, identified as CVE-2026-20266, which has a CVSS score of 9.1. This flaw allows an admin user to execute arbitrary commands on the host system. Alongside this, four additional vulnerabilities have been disclosed across Splunk products, all of which currently have no confirmed active exploitation. Users are advised to update to specified versions to mitigate these risks. The vulnerabilities primarily impact older versions of Splunk AI Toolkit and Splunk Enterprise.

View Primary Source Via securityonline.info

Article by CyberSIXT