Atlassian, Splunk Patch Critical Vulnerabilities
Atlassian and Splunk on Wednesday announced patches for multiple vulnerabilities in their products, including critical-severity flaws.
Splunk resolved a critical issue in AI Toolkit that could allow authenticated attackers with admin roles to execute arbitrary OS commands on the host the Splunk Enterprise instance runs on.
“The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation,” Splunk explains.
Tracked as CVE-2026-20266 (CVSS score of 9.1), the security defect was addressed in Splunk AI Toolkit version 5.7.4. If upgrading is not possible, Splunk recommends uninstalling the AI Toolkit as a mitigation.
The update also addresses CVE-2026-20265, a medium-severity information disclosure bug caused by an insecure default domain allowlist. An attacker holding the admin or power role could cause the AI Toolkit to make outbound HTTP requests to attacker-controlled servers, leading to data exfiltration.
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE