惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
Jina AI
Jina AI
量子位
博客园 - 叶小钗
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
博客园 - 聂微东
美团技术团队
Last Week in AI
Last Week in AI
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园_首页
V
Visual Studio Blog
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Splunk AI Toolkit Vulnerability Enables Arbitrary OS Comm...
Abinaya · 2026-06-18 · via Cyber Security News

Splunk has disclosed a critical security vulnerability in its AI Toolkit that could allow attackers to execute arbitrary operating system commands on affected systems.

The flaw, tracked as CVE-2026-20266, has been assigned a CVSS score of 9.1, highlighting its severe impact on enterprise environments.

It affects Splunk AI Toolkit versions below 5.7.4 and is categorized under CWE-78, which refers to OS command injection issues.

According to Splunk, the flaw exists in the btool configuration helper. This component handles configuration-related operations within the toolkit.

The root cause of the vulnerability lies in an unsafe shell execution pattern. The btool helper constructs OS command strings using dynamic input parameters without properly sanitizing or disabling shell interpretation.

This insecure design allows specially crafted input to inject and execute arbitrary commands at the operating system level. An attacker with administrative privileges in Splunk can exploit this flaw to run malicious commands on the host system.

Because the vulnerability does not require user interaction and can be executed remotely, it significantly increases the risk in enterprise deployments.

The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) indicates that while high privileges are required, the attack complexity is low and can result in full compromise of confidentiality, integrity, and availability.

Successful exploitation of CVE-2026-20266 could allow attackers to execute arbitrary system commands on the Splunk host. Access or modify sensitive data within the environment. Disrupt system operations or services. Potentially pivot to other systems within the network.

Given that Splunk is widely used for security monitoring and log analysis, compromising such a system could severely impact an organization’s visibility and incident response capabilities.

The vulnerability affects the following versions: Splunk AI Toolkit 5.7 and earlier versions below 5.7.4. Systems running version 5.7.4 or later are not affected.

Splunk strongly recommends upgrading to version 5.7.4 or higher to remediate the issue. The patched version addresses the unsafe shell execution behavior and prevents command injection.

As an immediate workaround, organizations can uninstall the Splunk AI Toolkit if upgrading is not feasible. Splunk provides guidance on managing and removing apps in its official documentation.

Currently, there are no specific detection mechanisms or indicators of compromise (IOCs) associated with this vulnerability, making proactive patching critical.

The vulnerability, tracked in advisory SVD-2026-0614 and published on June 17, 2026, was discovered and reported by Gabriel Nitu of Splunk. At the time of publication, there was no public evidence of active exploitation of the flaw.

Organizations using Splunk AI Toolkit should: Immediately identify and upgrade vulnerable instances. Restrict administrative access to trusted users only.

Monitor system activity for unusual command execution patterns. Apply least-privilege principles across Splunk roles.

Given the critical nature of this vulnerability, timely remediation is essential to prevent potential exploitation and maintain the integrity of security operations.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.