Splunk disclosed a critical vulnerability in Splunk AI Toolkit that allows OS command injection through the btool Configuration Helper, affecting versions earlier than 5.7.4. Tracked as CVE-2026-20266 and rated CVSS 9.1, the flaw stems from unsafe shell execution that can let a user with the Splunk admin role run arbitrary commands on the host running Splunk Enterprise, creating a direct path to host compromise.
Splunk also fixed CVE-2026-20265, a lower-severity insecure default domain allowlist issue rated CVSS 4.3 that could allow a low-privileged user to trigger outbound HTTP requests and potentially exfiltrate data to an attacker-controlled server. The Canadian Centre for Cyber Security highlighted the vendor advisory in AV26-614 and urged administrators to review Splunk’s guidance and upgrade to version 5.7.4 or later; public reporting said there was no confirmed exploitation in the wild at disclosure time.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-18, Atlassian announced security updates covering dozens of vulnerabilities across multiple Data Center and Server products, largely tied to third-party dependencies such as Axios, Apache Tomcat, and Netty. The company addressed several critical-severity CVEs through product updates and urged users to upgrade promptly.
On 2026-06-17, the Canadian Centre for Cyber Security published advisory AV26-614 highlighting Splunk's security update, including the critical Splunk AI Toolkit issue. The advisory urged users and administrators to review Splunk's advisories and apply the necessary updates.
On 2026-06-17, Splunk published security advisories for vulnerabilities in Splunk AI Toolkit, including CVE-2026-20266, a critical OS command injection flaw in the btool Configuration Helper affecting versions earlier than 5.7.4. The advisories indicate the issues are fixed in version 5.7.4 and users should apply the update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcesecurityonline.info
Open sourceadvisory.splunk.com
Open sourcecve.org
Open sourceconfluence.atlassian.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.