Executive brief
Splunk Enterprise and Cloud Platform are data analysis tools used by organizations to monitor and search machine-generated data. A security flaw in the Splunk Secure Gateway component allows a user with low-level access to execute unauthorized commands on the server. This could lead to a complete system takeover, data theft, or disruption of monitoring services.
Technical details
An unsafe deserialization vulnerability exists in the Splunk Secure Gateway app within Splunk Enterprise and Splunk Cloud Platform. The issue stems from the use of the 'jsonpickle' Python library to process App Key Value Store (KV Store) data without sufficient validation. An authenticated, low-privileged attacker can exploit this by providing specially crafted JSON data that, when deserialized, reconstructs arbitrary Python objects. Successful exploitation allows for remote code execution (RCE) on the affected Splunk instance. Patches are available in Splunk Enterprise versions 10.2.4, 10.0.7, 9.4.12, 9.3.13, and higher.
Affected products
- Splunk Splunk Enterprise Below 10.2.4, 10.0.7, 9.4.12, 9.3.13
- Splunk Splunk Cloud Platform Below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, 9.3.2411.132
- Splunk Splunk Secure Gateway Below 3.10.6, 3.9.20, 3.8.67
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory
- 2026-06-10: patched