Splunk disclosed and fixed CVE-2026-20266, a critical OS command injection flaw in the Splunk AI Toolkit's btool configuration helper that can let a user with the Splunk admin role execute arbitrary operating system commands on the underlying host. The vulnerability is classified as CWE-78 and carries a CVSS 9.1 score; it stems from unsafe shell execution in which dynamic parameters are concatenated into a shell-interpreted command string, potentially allowing injected commands to run with the privileges of the splunkd service account.
The issue affects Splunk AI Toolkit versions earlier than 5.7.4 in the 5.7.x branch and requires the AI Toolkit to be installed and active for exploitation. Splunk addressed the flaw in version 5.7.4, and downstream security notices have highlighted the update as part of broader Splunk security guidance. Reporting on the bug also noted similarities to CVE-2026-20163, pointing to a recurring risk pattern around shell interpretation in privileged Splunk components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
EG-FinCIRT published a Splunk security update. The reference indicates the update was issued on 21 June 2026, but no additional event details are provided in the supplied content.
ZeroPath published a write-up describing CVE-2026-20266 as a critical command injection vulnerability in the Splunk AI Toolkit's btool configuration helper. The post states the flaw is caused by unsafe shell execution, maps to CWE-78, and carries a CVSS score of 9.1.
Splunk fixed a critical OS command injection flaw in the Splunk AI Toolkit by publishing version 5.7.4. The issue affects versions below 5.7.4 in the 5.7.x line and allows a Splunk admin to execute arbitrary OS commands on the host when the toolkit is installed and active.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.