Threat reportVulnerabilityTL-2026-0877
Splunk AI Toolkit OS Command Injection in btool Configuration Helper (CVE-2026-20266)
Splunk AI Toolkit OS Command Injection in btool (TL-2026-0877), also tracked as SVD-2026-0614, is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-06-19. It has no confirmed attribution, affects Splunk (Cisco) Splunk AI Toolkit, references 2 CVEs (CVE-2026-20266, CVE-2026-20265), maps to 15 MITRE ATT&CK techniques (T1005, T1021, T1059), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 9.1/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0877
- Threat ID
- TL-2026-0877
- Also known as
- SVD-2026-0614, CERTFR-2026-AVI-0774, VULN-65723
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, financial, government, healthcare, telecommunications, managed-security-services
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
How Splunk AI Toolkit OS Command Injection in btool works
Splunk AI Toolkit versions below 5.7.4 contain a critical OS command injection flaw (CWE-78, CVSS 9.1) in the btool configuration helper, which builds OS command strings from dynamic parameters without disabling shell interpretation. An authenticated user holding the Splunk admin role can inject and execute arbitrary OS commands on the host running Splunk Enterprise. Fixed in AI Toolkit 5.7.4.
CVE-2026-20266 is an OS command injection vulnerability in the btool configuration helper of the Splunk AI Toolkit, disclosed by Splunk in advisory SVD-2026-0614 on 2026-06-17 and credited to Splunk's own Gabriel Nitu. The btool helper is used by the toolkit to read and validate Splunk configuration (.conf) state. The vulnerable code path constructs an OS command string by interpolating dynamic, user-influenced input parameters and then executes it with shell interpretation enabled (an unsafe shell-execution pattern, e.g. invoking a subprocess with shell=True or passing an unescaped string to a system shell). Because special shell metacharacters in the dynamic parameters are neither neutralized nor escaped, an attacker can break out of the intended btool command and append arbitrary commands (using `;`, `|`, `&&`, `$(...)`, backticks, etc.), which the shell then executes in the security context of the Splunk service process.
The vulnerability is reachable over the network (AV:N) through the authenticated Splunk web/REST surface and requires high privileges (PR:H): the attacker must already hold the Splunk "admin" role. No user interaction is required (UI:N), attack complexity is low (AC:L), and the scope is changed (S:C) because the injected command executes outside the application sandbox at the operating-system level, on the host running the Splunk Enterprise instance. Successful exploitation yields complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H): the attacker can read or modify any data accessible to the Splunk service account, disrupt the Splunk service, establish persistence, and pivot laterally to other systems reachable from the Splunk host.
The issue is fixed in Splunk AI Toolkit 5.7.4, which corrects the unsafe shell execution (parameterized/escaped invocation rather than string-built shell commands). Where upgrading is not immediately feasible, Splunk recommends uninstalling the AI Toolkit add-on to eliminate the exposed code path. A related lower-severity issue, CVE-2026-20265 (CVSS 4.3), was patched in the same 5.7.4 release: it concerns an insecure default domain allowlist that allowed admin/power-role users to trigger unauthorized outbound HTTP requests; it is mitigated by defining approved domains under `[ai:AllowedDomains]` in mlspl.conf and enabling `enforce_domain_validation`. At the time of publication there was no evidence of public proof-of-concept exploit code and no observed in-the-wild exploitation, and no network IOCs (C2 infrastructure, malware hashes, domains/IPs) are associated with this vulnerability; detection therefore focuses on host-level behavioral indicators of shell execution spawned by the Splunk service.
MITRE ATT&CK techniques used in TL-2026-0877
Collection
Lateral Movement
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Defense Evasion
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Impact
Persistence
T1505 Server Software Component; T1543 Create or Modify System Process
Credential Access
Exfiltration
Affected products and versions in Splunk AI Toolkit OS Command Injection in btool
- Splunk (Cisco) — Splunk AI Toolkit
Vulnerable versions: < 5.7.4; 5.7.0; 5.7.1; 5.7.2; 5.7.3
Fixed in: 5.7.4
Remediation for Splunk AI Toolkit OS Command Injection in btool
Patches
- Splunk AI Toolkit 5.7.4 (fixes CVE-2026-20266 and CVE-2026-20265) per advisory SVD-2026-0614.
Immediate actions
- Upgrade Splunk AI Toolkit to version 5.7.4 or higher on all Splunk Enterprise instances where it is installed.
- If upgrading is not immediately feasible, uninstall the Splunk AI Toolkit add-on to remove the vulnerable btool helper code path.
- Audit and restrict the Splunk 'admin' role to a minimal set of trusted users; remove unnecessary admin grants.
Workarounds
- Uninstall the Splunk AI Toolkit if 5.7.4 cannot be deployed.
- For the related CVE-2026-20265, define approved domains under [ai:AllowedDomains] in mlspl.conf and set enforce_domain_validation.
Longer-term hardening
- Apply least-privilege across Splunk roles and capabilities; avoid using admin accounts for routine operations.
- Run Splunk as an unprivileged service account and apply OS-level hardening (no shell for the service account where practical, restricted PATH).
- Deploy host/EDR monitoring on Splunk servers to alert on shell processes spawned by the Splunk service (splunkd / python) and on outbound connections from the Splunk host.
- Enable and review Splunk audit logging for configuration and toolkit actions; alert on btool invocations containing shell metacharacters.
CVEs associated with Splunk AI Toolkit OS Command Injection in btool
Weaknesses (CWE) in Splunk AI Toolkit OS Command Injection in btool
Timeline of Splunk AI Toolkit OS Command Injection in btool
- Splunk assigns internal bug identifier VULN-65723 to the issue in SVD-2026-0614 and notes that no vendor detection signatures are available for CVE-2026-20266.
- Security press (Cyber Security News, GBHackers, SecurityWeek, Cyberpress) report the critical AI Toolkit command-injection flaw.
- NVD record for CVE-2026-20266 last modified at 20:17 UTC on the same day.
- CVE-2026-20266 published in the NVD at 18:17 UTC with CVSS:3.1 9.1 (CRITICAL) and CWE-78; status 'Undergoing Analysis'.
- Fix released in Splunk AI Toolkit 5.7.4, which also addresses the related CVE-2026-20265 domain-allowlist issue.
- Splunk publishes advisory SVD-2026-0614 disclosing the btool configuration helper OS command injection (CVE-2026-20266, CVSS 9.1).
- Vulnerability identified and reported internally by Gabriel Nitu of Splunk (credited in SVD-2026-0614).
- Third-party vulnerability trackers (CIRCL Vulnerability-Lookup, ThreatINT) aggregate CVE-2026-20266 for community consumption.
- French national CERT (ANSSI) tracks the issue via advisory CERTFR-2026-AVI-0774.
Sources cited for Splunk AI Toolkit OS Command Injection in btool
- OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit (SVD-2026-0614)
- NVD - CVE-2026-20266
- Splunk AI Toolkit Vulnerability Let Attackers Execute Arbitrary Commands
- Splunk AI Toolkit Vulnerability Allows Arbitrary OS Command Execution
- Atlassian, Splunk Patch Critical Vulnerabilities
- Critical Splunk AI Toolkit Flaw Enables Arbitrary OS Command Execution
- CERTFR-2026-AVI-0774 (Vulnerability-Lookup)
- CWE-78: Improper Neutralization of Special Elements used in an OS Command
Detection coverage for TL-2026-0877
As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0877 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.