CVE Explorer
CVE-2026-20266
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance.
The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-78","description":"The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.","lang":"en","type":"cwe"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c5585a1f1331e98bbd939d5c0347ef4a176e06096ef9c0baab68525de977a33a · sha256:c6d11661ea345d43… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c5585a1f1331e98bbd939d5c0347ef4a176e06096ef9c0baab68525de977a33a · sha256:c6d11661ea345d43… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"Splunk AI Toolkit","vendor":"Splunk","versions":[{"lessThan":"5.7.4","status":"affected","version":"5.7","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c5585a1f1331e98bbd939d5c0347ef4a176e06096ef9c0baab68525de977a33a · sha256:c6d11661ea345d43… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c5585a1f1331e98bbd939d5c0347ef4a176e06096ef9c0baab68525de977a33a · sha256:c6d11661ea345d43… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-78","description":"The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.","lang":"en","type":"cwe"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c5585a1f1331e98bbd939d5c0347ef4a176e06096ef9c0baab68525de977a33a · sha256:c6d11661ea345d43… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c5585a1f1331e98bbd939d5c0347ef4a176e06096ef9c0baab68525de977a33a · sha256:c6d11661ea345d43… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://advisory.splunk.com/advisories/SVD-2026-0614"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5585a1f1331e98bbd939d5c0347ef4a176e06096ef9c0baab68525de977a33a · sha256:c6d11661ea345d43… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.