🔐 CVE Alert

CVE-2026-20251

HIGH 8.8

Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.

CWE CWE-502
Vendor splunk
Product splunk enterprise
Published Jun 10, 2026
Last Updated Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for splunk splunk enterprise

Be the first to know when new high vulnerabilities affecting splunk splunk enterprise are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Splunk / Splunk Enterprise
10.2 < 10.2.4 10.0 < 10.0.7 9.4 < 9.4.12 9.3 < 9.3.13
Splunk / Splunk Cloud Platform
10.3.2512 < 10.3.2512.12 10.2.2510 < 10.2.2510.14 10.1.2507 < 10.1.2507.22 9.3.2411 < 9.3.2411.132
Splunk / Splunk Secure Gateway
3.10 < 3.10.6 3.9 < 3.9.20 3.8 < 3.8.67

References

NVD ↗ CVE.org ↗ EPSS Data ↗
advisory.splunk.com: https://advisory.splunk.com/advisories/SVD-2026-0601

Credits

M Mahdan Argya Syarif (0xbeludan)