CVE-2026-20266Patch(splunk / ai_toolkit)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk ai_toolkit systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ai_toolkit

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-06-17); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
ai_toolkit

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-06-17: 2Mentions · 2026-06-18: 1Mentions · 2026-06-25: 1Mentions · 2026-08-20: 2Mentions · 2026-08-21: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-08-20: 2Technical Details · 2026-06-17: 2Technical Details · 2026-06-18: 1Technical Details · 2026-06-25: 1Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 106-1706-1806-2508-2008-21
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-172
Disclosure1Patch1
2026-06-181
Patch1
2026-06-251
Patch1
2026-08-202
Disclosure1Patch1
2026-08-211
Disclosure1
Full discourse7 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Critical OS command injection in Splunk AI Toolkit (CVE-2026-20266, CVSS 9.1) lets admins run arbitrary host commands. Patch to 5.7.4 now. #Splunk #CVE #OSCommandInjection #Vulnerability #InfoSec #PatchNow #AISecurity https://securityonline.info/splunk-ai-toolkit-cve-2026-20266/

    Post summary

    The tweet highlights a critical OS command injection in Splunk AI Toolkit (CVE-2026-20266, CVSS 9.1) and urges users to apply the patch to version 5.7.4.

    03061517
    12.9K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Splunk AI Toolkitに重大(Critical)な脆弱性。CVE-2026-20266はCVSSスコア9.1のOSコマンドインジェクション。要管理者アカウント。他脆弱性と併せ修正。 https://securityonline.info/splunk-ai-toolkit-cve-2026-20266/

    Post summary

    Splunk AI Toolkit contains a critical OS command injection flaw (CVE‑2026‑20266, CVSS 9.1) requiring administrator rights, and a combined patch with other vulnerabilities is available.

    01030766
    7.8K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    New Splunk AI Toolkit vulnerabilities, including severe OS command injection (CVE-2026-20266), expose systems to attacks. Patch your instances immediately. #Splunk #CyberSecurity #CVE202620266 #CVE202620265 #Vulnerability https://securityonline.info/splunk-ai-toolkit-vulnerabilities https://t.co/o4gUsTwhGx

    Post summary

    The post reports new Splunk AI Toolkit vulnerabilities, notably a severe OS command injection (CVE‑2026‑20266), and urges users to patch immediately.

    01021373
    12.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Splunk AI Toolkit の脆弱性 CVE-2026-20266 が FIX:任意の OS コマンド実行の恐れ https://iototsecnews.jp/2026/06/18/splunk-ai-toolkit-vulnerability-enables-arbitrary-os-command-execution-attacks/ Splunk AI Toolkit の脆弱性 CVE-2026-20266 は、分析を補助する拡張ツール内の設定支援機能において、外部から送られてきた文字列を OS への命令として組み立ててしまう、設計上の不備に起因します。それにより、特別な操作を経ずにシステムの根幹で任意のコマンドを実行され、監視網の破壊や内部データの改竄などを招く可能性が生じてしまいます。対応策としては、不備が解消された5.7.4以降のバージョンへ直ちに更新するとともに、管理画面に触れる役割の権限を必要最小限に絞る必要があります。 #AIToolkit #CVE202620266 #Splunk #Vulnerability

    Post summary

    Splunk AI Toolkit CVE-2026-20266 allows arbitrary OS command execution; the vendor has fixed the issue in version 5.7.4 and advises immediate update and least‑privilege permissions.

    01000124
    501 followersView on X
  • キタきつね@foxbook
    Disclosure

    Splunk AI Toolkitに深刻なOSコマンドインジェクションの脆弱性(CVE-2026-20266、CVSS 9.1)が発覚 CVE-2026-20266: Critical OS Command Injection Hits Splunk AI Toolkit (CVSS 9.1) #DailyCyberSecurity (Aug 20) https://securityonline.info/splunk-ai-toolkit-cve-2026-20266/

    Post summary

    The post announces the discovery of CVE-2026-20266, a critical OS command injection affecting Splunk AI Toolkit with a CVSS score of 9.1, but does not provide a PoC, exploit, or patch information.

    00000290
    4.9K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🛡️ Splunk has patched a critical AI Toolkit flaw (CVE-2026-20266) that lets admins execute arbitrary OS commands on affected systems. The bug impacts versions below 5.7.4 and could lead to full system compromise. Patch ASAP. #Splunk #CyberSecurity Read more: https://thecyberedition.com/splunk-ai-toolkit-flaw-lets-admins-run-arbitrary-os-commands/

    Post summary

    Splunk has addressed CVE‑2026‑20266 with a patch, fixing a flaw that allowed administrators to run arbitrary OS commands on pre‑5.7.4 AI Toolkit installations, potentially compromising systems.

    0000062
    741 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20266 In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise inst… https://www.cve.org/CVERecord?id=CVE-2026-20266

    Post summary

    The CVE-2026-20266 issue allows a Splunk admin user to execute arbitrary OS commands on hosts running Splunk AI Toolkit versions below 5.7.4.

    00000231
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunkai_toolkit---

Explore more