CVE-2026-20251 is a high-severity remote code execution vulnerability affecting Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway when the Splunk Secure Gateway app is present in affected versions. The flaw is caused by unsafe deserialization of App Key Value Store data through the jsonpickle Python library. Specifically, attacker-controlled JSON stored in KV Store data can be passed to jsonpickle for reconstruction of Python objects without sufficient validation, allowing crafted serialized content to instantiate arbitrary objects and trigger code execution during deserialization. The issue is exploitable by an authenticated low-privileged Splunk user who does not hold the admin or power roles, making the attack surface broader than similar Splunk deserialization issues that required higher privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small proof-of-concept package for CVE-2026-20251 affecting Splunk Secure Gateway. It contains one executable Python PoC (poc_cve_2026_20251.py) plus supporting documentation in README.md, hashnode-article.md, and engagement.json. The PoC is not a full end-to-end remote exploit client; instead it demonstrates the two critical exploit primitives that compose the real attack chain: (1) bypass of Splunk Secure Gateway's check_alert_data_valid_json() validator by placing an allowed top-level 'py/object' key first and hiding a malicious sibling 'notification' value containing a py/reduce gadget, and (2) execution of that gadget through jsonpickle.decode(..., safe=True), proving the safe flag does not block py/reduce/function/object restoration paths. The exploit capability described by the repository is authenticated remote code execution on the Splunk host as the Splunk service account, achieved by writing a crafted document into the 'mobile_alerts' KV Store collection via Splunk's REST/API workflow and waiting for Secure Gateway to deserialize it. The included payload is intentionally benign: subprocess.check_output(['uname','-a']) to print system information. Fingerprintable targets and context include the local test host 127.0.0.1, Splunk management port 8089, KV Store/mongod port 8191, the SSG bundled library path /Applications/Splunk/etc/apps/splunk_secure_gateway/lib, and vulnerable source files under bin/spacebridgeapp/. Overall, this is a credible, non-weaponized Python POC focused on vulnerability verification and exploit-chain explanation rather than automated exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity authenticated remote code execution vulnerability in Splunk Secure Gateway caused by unsafe jsonpickle deserialization and a validator bypass in the alert processing pipeline.
A remote code execution vulnerability in Splunk Secure Gateway caused by deserialization of untrusted data, mentioned for background context.
A Splunk Secure Gateway and App Key Value Store insecure deserialization vulnerability caused by use of jsonpickle. An attacker with low-privilege access who can write crafted payloads to KV Store can achieve code execution.
A remote code execution vulnerability in Splunk Enterprise's Splunk Secure Gateway application caused by unsafe deserialization of App Key Value Store data through the jsonpickle Python library.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.