CVE-2026-20251
largeLow-Privilege RCE in Splunk Secure Gateway via Unsafe JSON Deserialization
CVE-2026-20251 is an insecure deserialization vulnerability (CWE-502) in the Splunk Secure Gateway app that can lead to remote code execution on Splunk Enterprise and Splunk Cloud Platform. A low-privileged user who does not hold the 'admin' or 'power' roles can trigger it through the Secure Gateway app: specially crafted JSON stored in the App Key Value Store (KV Store) is deserialized by the 'jsonpickle' Python library, which reconstructs arbitrary Python objects without adequate validation. Successful exploitation gives the attacker arbitrary code execution on the affected Splunk instance, with high impact to confidentiality, integrity, and availability reflected in the 8.8 (High) CVSS 3.1 score. All Splunk Enterprise deployments below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform deployments below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Secure Gateway app versions below 3.10.6, 3.9.20, and 3.8.67 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known and the issue is not yet in CISA KEV, but the EPSS score of 32.2% (98th percentile) signals an elevated likelihood of exploitation within 30 days.
What to do: Upgrade Splunk Enterprise to 10.2.4, 10.0.7, 9.4.12, or 9.3.13 (or later on each line) and the Splunk Secure Gateway app to 3.10.6, 3.9.20, or 3.8.67 as applicable; Splunk Cloud Platform instances should be brought to 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, or 9.3.2411.132 via Splunk's managed update process. Until patched, restrict access to Splunk web, audit and minimize accounts that lack the admin or power roles, and monitor for unexpected child processes spawned by the Splunk service. Given the elevated EPSS score, treat patching as high priority.
| Splunk Enterprise | Below 10.2.4, 10.0.7, 9.4.12, and 9.3.13 (respective release lines) |
| Splunk Cloud Platform | Below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132 |
| Splunk Secure Gateway (app) | Below 3.10.6, 3.9.20, and 3.8.67 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app. The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.
- Vendors
- splunk
- Products
- splunk, splunk cloud platform, splunk secure gateway
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.