Deserialization of Untrusted Data in Splunk Enterprise - CVE-2026-20251

 

Deserialization of Untrusted Data in Splunk Enterprise - CVE-2026-20251

Published: June 12, 2026


Vulnerability identifier: #VU134463
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20251
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in the Splunk Secure Gateway app when processing App Key Value Store data through the jsonpickle Python library. A remote user can supply specially crafted JSON data to execute arbitrary code.

The issue affects users that do not hold the admin or power Splunk roles.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-20251

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.3.13, 9.4.12, 10.0.7, 10.2.4

External References

Related Security Bulletins