CVE Explorer
CVE-2026-20265
In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker controls, which could allow for data exfiltration.
The vulnerability exists because of an insecure default domain allowlist in the Splunk AI Toolkit, which does not restrict outbound AI agent requests to approved external domains.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"Splunk AI Toolkit","vendor":"Splunk","versions":[{"lessThan":"5.7.4","status":"affected","version":"5.7","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6684c7284f90b2d557ee5689ed628b0b019c1c4ae7528105b22fde105a0ffe37 · sha256:9dc7642a7e0db359… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6684c7284f90b2d557ee5689ed628b0b019c1c4ae7528105b22fde105a0ffe37 · sha256:9dc7642a7e0db359… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1188","description":"The software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.","lang":"en","type":"cwe"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6684c7284f90b2d557ee5689ed628b0b019c1c4ae7528105b22fde105a0ffe37 · sha256:9dc7642a7e0db359… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://advisory.splunk.com/advisories/SVD-2026-0613"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6684c7284f90b2d557ee5689ed628b0b019c1c4ae7528105b22fde105a0ffe37 · sha256:9dc7642a7e0db359… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.