Threat reportVulnerabilityTL-2026-0877

Splunk AI Toolkit OS Command Injection in btool Configuration Helper (CVE-2026-20266)

criticalACTIVE

Splunk AI Toolkit OS Command Injection in btool (TL-2026-0877), also tracked as SVD-2026-0614, is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-06-19. It has no confirmed attribution, affects Splunk (Cisco) Splunk AI Toolkit, references 2 CVEs (CVE-2026-20266, CVE-2026-20265), maps to 15 MITRE ATT&CK techniques (T1005, T1021, T1059), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
9.1/10Critical
CVEs
2Referenced vulnerabilities
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0877

Threat ID
TL-2026-0877
Also known as
SVD-2026-0614, CERTFR-2026-AVI-0774, VULN-65723
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, financial, government, healthcare, telecommunications, managed-security-services
Target regions
Global
Detection rules
9
Indicators of compromise
16

How Splunk AI Toolkit OS Command Injection in btool works

Splunk AI Toolkit versions below 5.7.4 contain a critical OS command injection flaw (CWE-78, CVSS 9.1) in the btool configuration helper, which builds OS command strings from dynamic parameters without disabling shell interpretation. An authenticated user holding the Splunk admin role can inject and execute arbitrary OS commands on the host running Splunk Enterprise. Fixed in AI Toolkit 5.7.4.

CVE-2026-20266 is an OS command injection vulnerability in the btool configuration helper of the Splunk AI Toolkit, disclosed by Splunk in advisory SVD-2026-0614 on 2026-06-17 and credited to Splunk's own Gabriel Nitu. The btool helper is used by the toolkit to read and validate Splunk configuration (.conf) state. The vulnerable code path constructs an OS command string by interpolating dynamic, user-influenced input parameters and then executes it with shell interpretation enabled (an unsafe shell-execution pattern, e.g. invoking a subprocess with shell=True or passing an unescaped string to a system shell). Because special shell metacharacters in the dynamic parameters are neither neutralized nor escaped, an attacker can break out of the intended btool command and append arbitrary commands (using `;`, `|`, `&&`, `$(...)`, backticks, etc.), which the shell then executes in the security context of the Splunk service process.

The vulnerability is reachable over the network (AV:N) through the authenticated Splunk web/REST surface and requires high privileges (PR:H): the attacker must already hold the Splunk "admin" role. No user interaction is required (UI:N), attack complexity is low (AC:L), and the scope is changed (S:C) because the injected command executes outside the application sandbox at the operating-system level, on the host running the Splunk Enterprise instance. Successful exploitation yields complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H): the attacker can read or modify any data accessible to the Splunk service account, disrupt the Splunk service, establish persistence, and pivot laterally to other systems reachable from the Splunk host.

The issue is fixed in Splunk AI Toolkit 5.7.4, which corrects the unsafe shell execution (parameterized/escaped invocation rather than string-built shell commands). Where upgrading is not immediately feasible, Splunk recommends uninstalling the AI Toolkit add-on to eliminate the exposed code path. A related lower-severity issue, CVE-2026-20265 (CVSS 4.3), was patched in the same 5.7.4 release: it concerns an insecure default domain allowlist that allowed admin/power-role users to trigger unauthorized outbound HTTP requests; it is mitigated by defining approved domains under `[ai:AllowedDomains]` in mlspl.conf and enabling `enforce_domain_validation`. At the time of publication there was no evidence of public proof-of-concept exploit code and no observed in-the-wild exploitation, and no network IOCs (C2 infrastructure, malware hashes, domains/IPs) are associated with this vulnerability; detection therefore focuses on host-level behavioral indicators of shell execution spawned by the Splunk service.

MITRE ATT&CK techniques used in TL-2026-0877

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Defense Evasion

T1070 Indicator Removal

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Impact

T1489 Service Stop

Persistence

T1505 Server Software Component; T1543 Create or Modify System Process

Credential Access

T1552 Unsecured Credentials

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in Splunk AI Toolkit OS Command Injection in btool

  • Splunk (Cisco) — Splunk AI Toolkit
    Vulnerable versions: < 5.7.4; 5.7.0; 5.7.1; 5.7.2; 5.7.3
    Fixed in: 5.7.4

Remediation for Splunk AI Toolkit OS Command Injection in btool

Patches

  • Splunk AI Toolkit 5.7.4 (fixes CVE-2026-20266 and CVE-2026-20265) per advisory SVD-2026-0614.

Immediate actions

  • Upgrade Splunk AI Toolkit to version 5.7.4 or higher on all Splunk Enterprise instances where it is installed.
  • If upgrading is not immediately feasible, uninstall the Splunk AI Toolkit add-on to remove the vulnerable btool helper code path.
  • Audit and restrict the Splunk 'admin' role to a minimal set of trusted users; remove unnecessary admin grants.

Workarounds

  • Uninstall the Splunk AI Toolkit if 5.7.4 cannot be deployed.
  • For the related CVE-2026-20265, define approved domains under [ai:AllowedDomains] in mlspl.conf and set enforce_domain_validation.

Longer-term hardening

  • Apply least-privilege across Splunk roles and capabilities; avoid using admin accounts for routine operations.
  • Run Splunk as an unprivileged service account and apply OS-level hardening (no shell for the service account where practical, restricted PATH).
  • Deploy host/EDR monitoring on Splunk servers to alert on shell processes spawned by the Splunk service (splunkd / python) and on outbound connections from the Splunk host.
  • Enable and review Splunk audit logging for configuration and toolkit actions; alert on btool invocations containing shell metacharacters.

CVEs associated with Splunk AI Toolkit OS Command Injection in btool

CVE-2026-20266, CVE-2026-20265

Weaknesses (CWE) in Splunk AI Toolkit OS Command Injection in btool

CWE-78

Timeline of Splunk AI Toolkit OS Command Injection in btool

  • Splunk assigns internal bug identifier VULN-65723 to the issue in SVD-2026-0614 and notes that no vendor detection signatures are available for CVE-2026-20266.
  • Security press (Cyber Security News, GBHackers, SecurityWeek, Cyberpress) report the critical AI Toolkit command-injection flaw.
  • NVD record for CVE-2026-20266 last modified at 20:17 UTC on the same day.
  • CVE-2026-20266 published in the NVD at 18:17 UTC with CVSS:3.1 9.1 (CRITICAL) and CWE-78; status 'Undergoing Analysis'.
  • Fix released in Splunk AI Toolkit 5.7.4, which also addresses the related CVE-2026-20265 domain-allowlist issue.
  • Splunk publishes advisory SVD-2026-0614 disclosing the btool configuration helper OS command injection (CVE-2026-20266, CVSS 9.1).
  • Vulnerability identified and reported internally by Gabriel Nitu of Splunk (credited in SVD-2026-0614).
  • Third-party vulnerability trackers (CIRCL Vulnerability-Lookup, ThreatINT) aggregate CVE-2026-20266 for community consumption.
  • French national CERT (ANSSI) tracks the issue via advisory CERTFR-2026-AVI-0774.

Sources cited for Splunk AI Toolkit OS Command Injection in btool

Detection coverage for TL-2026-0877

As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0877 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats