← All Advisories

Splunk AI Toolkit Below 5.7.4 Constructs OS Command Strings from Dynamic btool Configuration Parameters Without Sanitization, Letting Admin-Role Users Execute Arbitrary OS Commands on the Host

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-20266

Key Details

CVECVE-2026-20266
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-06-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsSplunk ai_toolkit
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Splunkai_toolkit
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance.

The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation. (NVD)

What to Do

Monitor Splunk's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-20266
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-20266
Vendor advisoryhttps://advisory.splunk.com/advisories/SVD-2026-0614