Deserialization of Untrusted Data in Splunk Enterprise - CVE-2026-20251
Published: June 12, 2026
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in the Splunk Secure Gateway app when processing App Key Value Store data through the jsonpickle Python library. A remote user can supply specially crafted JSON data to execute arbitrary code.
The issue affects users that do not hold the admin or power Splunk roles.