Insecure Outbound Request Configuration in Splunk AI Toolkit
CVE-2026-20265
4.3MEDIUM
What is CVE-2026-20265?
The vulnerability in the Splunk AI Toolkit arises from an insecure default domain allowlist, permitting low-privileged users without 'admin' or 'power' roles to initiate outbound HTTP requests to external servers controlled by attackers. This misconfiguration can lead to unauthorized data exfiltration, as the toolkit fails to restrict requests to trusted domains.
Affected Version(s)
Splunk AI Toolkit 5.7 < 5.7.4