Critical command injection in Splunk AI Toolkit

Splunk has published SVD-2026-0614 for CVE-2026-20266, a critical OS command injection vulnerability in Splunk AI Toolkit versions below 5.7.4. Exploitation requires a user holding the Splunk admin role, but then allows arbitrary OS command execution on the host running the Splunk Enterprise instance, through unsafe shell execution in the btool configuration helper. Splunk fixed the issue in AI Toolkit 5.7.4 and recommends uninstalling the toolkit if upgrading is not possible.

What this means for your organisation

The Splunk server usually holds logs from across the business, and an attacker who can run commands there gains both visibility into your security data and the ability to erase their own traces. Requiring the admin role lowers the likelihood, but it also turns the question into how many people actually hold that role in your environment. This is also a reminder that AI add-ons get adopted quickly, often without the security review other software receives.

Berigo recommends

  • Upgrade Splunk AI Toolkit to 5.7.4, or uninstall the module if it is not actively used.
  • Review who holds the Splunk admin role and remove those who do not need it.
  • Ensure Splunk logs are replicated to storage that administrators on the Splunk host cannot alter.
  • Introduce a standing review of AI add-ons and extensions before they are installed in production.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch