# Splunk AI Toolkit OS Command Injection in btool Configuration Helper (CVE-2026-20266)

> Splunk AI Toolkit versions below 5.7.4 contain a critical OS command injection flaw (CWE-78, CVSS 9.1) in the btool configuration helper, which builds OS command strings from dynamic parameters without disabling shell interpretation. An authenticated user holding the Splunk admin role can inject and execute arbitrary OS commands on the host running Splunk Enterprise. Fixed in AI Toolkit 5.7.4.

- **Published:** 2026-06-19T00:00:00Z
- **Last reviewed:** 2026-06-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0877
- **ID:** TL-2026-0877
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-20266, CVE-2026-20265

## Description

CVE-2026-20266 is an OS command injection vulnerability in the btool configuration helper of the Splunk AI Toolkit, disclosed by Splunk in advisory SVD-2026-0614 on 2026-06-17 and credited to Splunk's own Gabriel Nitu. The btool helper is used by the toolkit to read and validate Splunk configuration (.conf) state. The vulnerable code path constructs an OS command string by interpolating dynamic, user-influenced input parameters and then executes it with shell interpretation enabled (an unsafe shell-execution pattern, e.g. invoking a subprocess with shell=True or passing an unescaped string to a system shell). Because special shell metacharacters in the dynamic parameters are neither neutralized nor escaped, an attacker can break out of the intended btool command and append arbitrary commands (using `;`, `|`, `&&`, `$(...)`, backticks, etc.), which the shell then executes in the security context of the Splunk service process.

The vulnerability is reachable over the network (AV:N) through the authenticated Splunk web/REST surface and requires high privileges (PR:H): the attacker must already hold the Splunk "admin" role. No user interaction is required (UI:N), attack complexity is low (AC:L), and the scope is changed (S:C) because the injected command executes outside the application sandbox at the operating-system level, on the host running the Splunk Enterprise instance. Successful exploitation yields complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H): the attacker can read or modify any data accessible to the Splunk service account, disrupt the Splunk service, establish persistence, and pivot laterally to other systems reachable from the Splunk host.

The issue is fixed in Splunk AI Toolkit 5.7.4, which corrects the unsafe shell execution (parameterized/escaped invocation rather than string-built shell commands). Where upgrading is not immediately feasible, Splunk recommends uninstalling the AI Toolkit add-on to eliminate the exposed code path. A related lower-severity issue, CVE-2026-20265 (CVSS 4.3), was patched in the same 5.7.4 release: it concerns an insecure default domain allowlist that allowed admin/power-role users to trigger unauthorized outbound HTTP requests; it is mitigated by defining approved domains under `[ai:AllowedDomains]` in mlspl.conf and enabling `enforce_domain_validation`. At the time of publication there was no evidence of public proof-of-concept exploit code and no observed in-the-wild exploitation, and no network IOCs (C2 infrastructure, malware hashes, domains/IPs) are associated with this vulnerability; detection therefore focuses on host-level behavioral indicators of shell execution spawned by the Splunk service.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1505 Server Software Component
- T1543 Create or Modify System Process
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1070 Indicator Removal
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1552 Unsecured Credentials
- T1005 Data from Local System
- T1021 Remote Services
- T1489 Service Stop
- T1567 Exfiltration Over Web Service

## Sources

- [OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit (SVD-2026-0614)](https://advisory.splunk.com/advisories/SVD-2026-0614)
- [NVD - CVE-2026-20266](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20266)
- [Splunk AI Toolkit Vulnerability Let Attackers Execute Arbitrary Commands](https://cybersecuritynews.com/splunk-ai-toolkit-vulnerability/)
- [Splunk AI Toolkit Vulnerability Allows Arbitrary OS Command Execution](https://gbhackers.com/splunk-ai-toolkit-vulnerability/)
- [Atlassian, Splunk Patch Critical Vulnerabilities](https://www.securityweek.com/atlassian-splunk-patch-critical-vulnerabilities/)
- [Critical Splunk AI Toolkit Flaw Enables Arbitrary OS Command Execution](https://cyberpress.org/critical-splunk-ai-toolkit-flaw/)
- [CERTFR-2026-AVI-0774 (Vulnerability-Lookup)](https://vulnerability.circl.lu/vuln/certfr-2026-avi-0774)
- [CWE-78: Improper Neutralization of Special Elements used in an OS Command](https://cwe.mitre.org/data/definitions/78.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0877
