cbcvebase.

Splunk Ai Toolkit vulnerabilities

3 known vulnerabilities affecting splunk/splunk_ai_toolkit.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-20266P2CRITICALCVSS 9.1≥ 5.7, < 5.7.42026-06-17
CVE-2026-20266 [CRITICAL] CWE-78 CVE-2026-20266: In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute ar In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without
cvelistv5nvd
CVE-2026-20238P3MEDIUMCVSS 6.5≥ 5.7, < 5.7.32026-05-20
CVE-2026-20238 [MEDIUM] CWE-863 CVE-2026-20238: In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or ' In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom roles.The app contains an `authorize.conf` configuration file with a `srchFilter` entry that modifies the built-in ‘user’ role. Because the S
nvd
CVE-2026-20265P4MEDIUMCVSS 4.3≥ 5.7, < 5.7.42026-06-17
CVE-2026-20265 [MEDIUM] CWE-1188 CVE-2026-20265: In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or " In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration. The vulnerability exists because of an insecure default domain allowlist in the
cvelistv5nvd
Splunk Ai Toolkit vulnerabilities | cvebase