# Splunk AI Toolkit RCE flaws patched

Published: 2026-06-18 · Severity: high
Canonical: https://vorant.io/reports/460b3537-8ff0-5b89-8733-aa5ba26cc46a/splunk-ai-toolkit-rce-flaws-patched

> Two vulnerabilities in Splunk AI Toolkit versions before 5.7.4 enable remote code execution and security policy bypass.

The French CERT-FR has issued an advisory regarding multiple vulnerabilities discovered in Splunk AI Toolkit affecting all versions prior to 5.7.4. The flaws, tracked as CVE-2026-20265 and CVE-2026-20266, allow an attacker to execute arbitrary code remotely and bypass security policies.

Splunk has released version 5.7.4 to address these vulnerabilities. Organizations running affected versions of the AI Toolkit should consult Splunk security bulletins SVD-2026-0613 and SVD-2026-0614 for detailed remediation guidance and apply the available patches promptly.

The advisory does not provide technical details about the vulnerability mechanisms or indicate active exploitation. The combination of remote code execution capability and security policy bypass represents a significant risk to organizations using the affected product versions.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20265, CVE-2026-20266

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0774/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/460b3537-8ff0-5b89-8733-aa5ba26cc46a/splunk-ai-toolkit-rce-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
