CVE-2026-20266: OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance.
The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk AI Toolkitto a version that resolves this vulnerability.Fixed in 5.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20266?
CVE-2026-20266 has a critical severity rating of 9.1.
How do I fix CVE-2026-20266?
To fix CVE-2026-20266, upgrade to Splunk AI Toolkit version 5.7.4 or later.
What type of vulnerability is CVE-2026-20266?
CVE-2026-20266 is categorized as an OS Command Injection vulnerability.
Who is affected by CVE-2026-20266?
Only users with the 'admin' Splunk role in Splunk AI Toolkit versions below 5.7.4 are affected by CVE-2026-20266.
What can an attacker do with CVE-2026-20266?
An attacker exploiting CVE-2026-20266 can execute arbitrary OS commands on the host running the Splunk Enterprise instance.