PT-2026-50501 · Splunk · Splunk Ai Toolkit

Published

2026-06-17

·

Updated

2026-06-17

·

CVE-2026-20265

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Splunk AI Toolkit versions prior to 5.7.4
Description A low-privileged user without "admin" or "power" Splunk roles can force the application to make outbound HTTP requests to an attacker-controlled server, potentially leading to data exfiltration. This occurs due to an insecure default domain allowlist that fails to restrict outbound AI agent requests to approved external domains.
Recommendations Update to version 5.7.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20265

Affected Products

Splunk Ai Toolkit