Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-20266

Опубликовано: 17 июн. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance.

The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:splunk:ai_toolkit:*:*:*:*:*:*:*:*
Версия от 5.7.0 (включая) до 5.7.4 (исключая)

EPSS

Процентиль: 38%
0.00469
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 9.1
github
около 2 месяцев назад

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.

CVSS3: 9.1
fstec
около 2 месяцев назад

Уязвимость инструмента btool Configuration Helper программного средства для работы с алгоритмами машинного обучения Splunk AI Tookit (AITK) (ранее Splunk Machine Learning Toolkit (MLTK)), позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 38%
0.00469
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-78
CWE-78