Executive brief
A vulnerability in the Splunk AI Toolkit allows a user with administrative privileges to execute unauthorized commands on the underlying server hosting Splunk Enterprise. This could lead to a complete takeover of the server, potentially resulting in data theft, service disruption, or further network intrusion. Organizations using this toolkit should update to the latest version to prevent administrative accounts from being leveraged for full system compromise.
Technical details
An OS command injection vulnerability (CWE-78) exists in the btool configuration helper component of the Splunk AI Toolkit. The flaw stems from an unsafe shell execution pattern where the application constructs OS command strings using dynamic parameters without properly disabling shell interpretation. An attacker with 'admin' role privileges can exploit this over the network to execute arbitrary commands on the Splunk Enterprise host. The vulnerability is resolved in version 5.7.4.
Affected products
- Splunk Splunk AI Toolkit < 5.7.4
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-17: patched