Home

Description

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.

PUBLISHED Reserved 2025-10-08 | Published 2026-06-10 | Updated 2026-06-10 | Assigner cisco




HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

Product status

10.2 (custom) before 10.2.4
affected

10.0 (custom) before 10.0.7
affected

9.4 (custom) before 9.4.12
affected

9.3 (custom) before 9.3.13
affected

10.3.2512 (custom) before 10.3.2512.12
affected

10.2.2510 (custom) before 10.2.2510.14
affected

10.1.2507 (custom) before 10.1.2507.22
affected

9.3.2411 (custom) before 9.3.2411.132
affected

3.10 (custom) before 3.10.6
affected

3.9 (custom) before 3.9.20
affected

3.8 (custom) before 3.8.67
affected

Credits

M Mahdan Argya Syarif (0xbeludan)

References

advisory.splunk.com/advisories/SVD-2026-0601

cve.org (CVE-2026-20251)

nvd.nist.gov (CVE-2026-20251)

Download JSON