ZeroHour

CVE-2026-20251

large

Low-Privilege RCE in Splunk Secure Gateway via Unsafe JSON Deserialization

CVSS 3.1
8.8 high
EPSS
32%p98
Published
()
Modified
AI analysis

CVE-2026-20251 is an insecure deserialization vulnerability (CWE-502) in the Splunk Secure Gateway app that can lead to remote code execution on Splunk Enterprise and Splunk Cloud Platform. A low-privileged user who does not hold the 'admin' or 'power' roles can trigger it through the Secure Gateway app: specially crafted JSON stored in the App Key Value Store (KV Store) is deserialized by the 'jsonpickle' Python library, which reconstructs arbitrary Python objects without adequate validation. Successful exploitation gives the attacker arbitrary code execution on the affected Splunk instance, with high impact to confidentiality, integrity, and availability reflected in the 8.8 (High) CVSS 3.1 score. All Splunk Enterprise deployments below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform deployments below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Secure Gateway app versions below 3.10.6, 3.9.20, and 3.8.67 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known and the issue is not yet in CISA KEV, but the EPSS score of 32.2% (98th percentile) signals an elevated likelihood of exploitation within 30 days.

What to do: Upgrade Splunk Enterprise to 10.2.4, 10.0.7, 9.4.12, or 9.3.13 (or later on each line) and the Splunk Secure Gateway app to 3.10.6, 3.9.20, or 3.8.67 as applicable; Splunk Cloud Platform instances should be brought to 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, or 9.3.2411.132 via Splunk's managed update process. Until patched, restrict access to Splunk web, audit and minimize accounts that lack the admin or power roles, and monitor for unexpected child processes spawned by the Splunk service. Given the elevated EPSS score, treat patching as high priority.

Affected
Splunk EnterpriseBelow 10.2.4, 10.0.7, 9.4.12, and 9.3.13 (respective release lines)
Splunk Cloud PlatformBelow 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132
Splunk Secure Gateway (app)Below 3.10.6, 3.9.20, and 3.8.67
Estimated exposure
large≈tens of thousands of Splunk Enterprise deployments (tens of thousands of Splunk instances routinely visible in public internet scans; the Secure Gateway app… — Estimated from public internet scans that consistently show on the order of tens of thousands of exposed Splunk instances and from deployment patterns in which the Secure Gateway app is bundled with Splunk Enterprise, with practical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app. The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.

Vendors
splunk
Products
splunk, splunk cloud platform, splunk secure gateway
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.