Количество 3
Количество 3
CVE-2026-20266
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.
GHSA-vxp7-5w84-27pf
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.
BDU:2026-08556
Уязвимость инструмента btool Configuration Helper программного средства для работы с алгоритмами машинного обучения Splunk AI Tookit (AITK) (ранее Splunk Machine Learning Toolkit (MLTK)), позволяющая нарушителю выполнить произвольные команды
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-20266 In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation. | CVSS3: 9.1 | 1% Низкий | около 2 месяцев назад | |
GHSA-vxp7-5w84-27pf In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation. | CVSS3: 9.1 | 1% Низкий | около 2 месяцев назад | |
BDU:2026-08556 Уязвимость инструмента btool Configuration Helper программного средства для работы с алгоритмами машинного обучения Splunk AI Tookit (AITK) (ранее Splunk Machine Learning Toolkit (MLTK)), позволяющая нарушителю выполнить произвольные команды | CVSS3: 9.1 | 1% Низкий | около 2 месяцев назад |
Уязвимостей на страницу