Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3040 articles · 162798 vulns · 38/41 feeds (7d)
← Back to list
8.8
CVE-2026-20251EXPLOITEDPATCHED
splunk · splunk enterprise

Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway

Description

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.

Affected Products

VendorProductVersions
splunksplunk enterprise10.2, 10.0, 9.4, 9.3, 10.3.2512, 10.2.2510, 10.1.2507, 9.3.2411, 3.10, 3.9, 3.8

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
splunksplunk enterprisecert_advisory90%

References

  • https://advisory.splunk.com/advisories/SVD-2026-0601

Related News (3 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] Splunk Enterprise: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-20251 | Splunk Enterprise/Cloud Platform/Secure Gateway App Key Value Store deserialization (SVD-2026-0601)
→ No new info (linked only)
Tier E
Hacker News4d ago
Splunk Enterprise PostgreSQL sidecar has no auth (CVE-2026-20253, CVSS 9.8)
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.2.410.0.79.4.129.3.1310.3.2512.1210.2.2510.1410.1.2507.229.3.2411.1323.10.63.9.203.8.67
CWECWE-502
PublishedJun 10, 2026
Last enriched4d agov2
Trending Score37
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20253
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
Trending: 60
CRITICALCVE-2026-20259EXP
Improper Access Control in Splunk Enterprise
Trending: 33
CRITICALCVE-2026-20254EXP
Information Disclosure through External Content Restriction Bypass in Splunk Enterprise
Trending: 33
CRITICALCVE-2026-20252EXP
Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise
Trending: 33
HIGHCVE-2026-20255EXP
Improper Input Validation through Classic Dashboards in Splunk Enterprise
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 10, 2026
Discovered by ZDM
Jun 10, 2026
Updated: severity, activelyExploited
Jun 10, 2026
Actively Exploited
Jun 11, 2026
Patch Available
Jun 11, 2026

Version History

v2
Last enriched 4d ago
v2Tier C4d ago

Updated severity to CRITICAL, marked as actively exploited, and noted that there is no available exploit.

severityactivelyExploited
via VulDB
v14d ago

Initial creation