Splunk Security Update – 21 June 2026

Splunk has released a security update to address two vulnerabilities affecting Splunk AI Toolkit.

The addressed vulnerabilities could allow the attacker to obtain sensitive information or execute arbitrary OS commands on the affected system.

The addressed vulnerabilities:

1. Splunk AI Toolkit OS Command Injection in the btool Configuration Helper Vulnerability (CVE-2026-20266):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Operating System Command Execution

2. Splunk AI Toolkit Insecure Default Domain Allowlist Vulnerability (CVE-2026-20265):

  • CVSS: 4.3
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information
Vulnerabilities
  • CVE-2026-20266
  • CVE-2026-20265
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Splunk Security Update

References