Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-security-bypass

Critical OS Command Injection Patched in Splunk AI Toolkit

Updated 23h agoFirst seen Jun 17, 20269 sources

Splunk disclosed a critical vulnerability in Splunk AI Toolkit that allows OS command injection through the btool Configuration Helper, affecting versions earlier than 5.7.4. Tracked as CVE-2026-20266 and rated CVSS 9.1, the flaw stems from unsafe shell execution that can let a user with the Splunk admin role run arbitrary commands on the host running Splunk Enterprise, creating a direct path to host compromise.

Splunk also fixed CVE-2026-20265, a lower-severity insecure default domain allowlist issue rated CVSS 4.3 that could allow a low-privileged user to trigger outbound HTTP requests and potentially exfiltrate data to an attacker-controlled server. The Canadian Centre for Cyber Security highlighted the vendor advisory in AV26-614 and urged administrators to review Splunk’s guidance and upgrade to version 5.7.4 or later; public reporting said there was no confirmed exploitation in the wild at disclosure time.

Share:
Critical OS Command Injection Patched in Splunk AI Toolkit
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 18, 20261d ago

Atlassian publishes 100 security bulletins for Data Center and Server products

On 2026-06-18, Atlassian announced security updates covering dozens of vulnerabilities across multiple Data Center and Server products, largely tied to third-party dependencies such as Axios, Apache Tomcat, and Netty. The company addressed several critical-severity CVEs through product updates and urged users to upgrade promptly.

Atlassian, Splunk Patch Critical Vulnerabilities - SecurityWeek
Jun 17, 20262d ago

Canadian Centre for Cyber Security issues advisory AV26-614

On 2026-06-17, the Canadian Centre for Cyber Security published advisory AV26-614 highlighting Splunk's security update, including the critical Splunk AI Toolkit issue. The advisory urged users and administrators to review Splunk's advisories and apply the necessary updates.

Splunk security advisory (AV26-614) - Canadian Centre for Cyber Security

Splunk discloses Splunk AI Toolkit vulnerabilities and releases version 5.7.4

On 2026-06-17, Splunk published security advisories for vulnerabilities in Splunk AI Toolkit, including CVE-2026-20266, a critical OS command injection flaw in the btool Configuration Helper affecting versions earlier than 5.7.4. The advisories indicate the issues are fixed in version 5.7.4 and users should apply the update.

CVE-2026-20266 - OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.