CVE-2026-20251: Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.4 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.3.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.3.2512.12 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.14 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.22 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 9.3.2411.132 - Upgrade
Upgrade
Splunk Secure Gatewayto a version that resolves this vulnerability.Fixed in 3.10.6 - Upgrade
Upgrade
Splunk Secure Gatewayto a version that resolves this vulnerability.Fixed in 3.9.20 - Upgrade
Upgrade
Splunk Secure Gatewayto a version that resolves this vulnerability.Fixed in 3.8.67
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20251?
CVE-2026-20251 has a high severity rating of 8.8.
How do I fix CVE-2026-20251?
To mitigate CVE-2026-20251, it is recommended to upgrade to Splunk Enterprise versions 10.2.4 or higher, or the appropriate updated versions of Splunk Cloud Platform and Splunk Secure Gateway.
What systems are affected by CVE-2026-20251?
CVE-2026-20251 affects Splunk Enterprise versions below 10.2.4, Splunk Cloud Platform versions below 10.3.2512.12, and Splunk Secure Gateway versions below 3.10.6.
What potential impact does CVE-2026-20251 have?
CVE-2026-20251 allows for remote code execution through deserialization of untrusted data by low-privileged users.
Is there a workaround for CVE-2026-20251?
Currently, the best approach for CVE-2026-20251 is to apply the necessary software upgrades, as no specific workaround is provided.