← Back to browse · API

CVE-2026-20251

Severity
HIGH
CVSS
8.8
EPSS
0.18991
Risk score
41.85
CISA KEV
No
PoC
No
Published
2026-06-10
Modified
2026-06-11
First seen
2026-08-07
Aliases
EUVD-2026-36082, GHSA-3CRW-7XG9-FPXG
Products
Splunk:Splunk Cloud Platform 10.1.2507 <10.1.2507.22, Splunk:Splunk Cloud Platform 10.2.2510 <10.2.2510.14, Splunk:Splunk Cloud Platform 10.3.2512 <10.3.2512.12, Splunk:Splunk Cloud Platform 9.3.2411 <9.3.2411.132, Splunk:Splunk Enterprise 10.0 <10.0.7, Splunk:Splunk Enterprise 10.2 <10.2.4, Splunk:Splunk Enterprise 9.3 <9.3.13, Splunk:Splunk Enterprise 9.4 <9.4.12, Splunk:Splunk Secure Gateway 3.10 <3.10.6, Splunk:Splunk Secure Gateway 3.8 <3.8.67, Splunk:Splunk Secure Gateway 3.9 <3.9.20
Sources
euvd EUVD-2026-36082

Description

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.

References