high CVSS 8.8

CVE-2026-20251·Python vulnerability

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.

Severity
high
Software
Python
Fixed in
3.10.6
Published
2026-06-10

Affected versions

From: 3.10.0

Until: 3.10.6

Fixed in: 3.10.6

How to fix this CVE

Update Splunk Secure Gateway to version 3.10.6 or later to remediate unsafe deserialization vulnerabilities in the KV Store integration. This vulnerability allows low-privileged users to execute arbitrary Python code by exploiting improper object reconstruction via the jsonpickle library. Immediate patching is critical as this affects all deployments regardless of role configuration.

sudo dnf update python3

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

POST requests to /api/kvstore/app_kv_store with JSON payloads containing __reduce__, __setstate__, or __dict__ attributes; or observation of unexpected Python subprocess/exec calls originating from splunkd processes handling KV Store operations

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Block or sanitize JSON payloads sent to Splunk Secure Gateway KV Store endpoints that contain Python object serialization markers (__reduce__, __setstate__, __dict__, __class__). Implement strict input validation on all KV Store write operations and enforce JSON schema validation to reject non-primitive objects.

How to check if you are affected

  1. Check installed Splunk Secure Gateway version: splunk show forward-server | grep version or review /opt/splunk/etc/apps/splunk_secure_gateway/default/app.conf
  2. Verify jsonpickle library presence and version: python3 -m pip show jsonpickle or find /opt/splunk -name 'jsonpickle*'
  3. Search KV Store transaction logs for suspicious JSON deserialization patterns: grep -r '__reduce__\|__setstate__\|__dict__' /opt/splunk/var/log/
  4. Confirm remediation by re-checking Splunk Secure Gateway version matches 3.10.6+ and comparing against advisory baseline

FAQ

What is CVE-2026-20251?

This is a remote code execution flaw in Splunk Secure Gateway caused by unsafe deserialization of Python objects from KV Store data. Attackers can craft malicious JSON payloads that reconstruct arbitrary Python objects, allowing code execution with the privileges of the Splunk process.

Is CVE-2026-20251 being actively exploited?

No active exploitation has been reported in the wild according to CISA KEV data, and no public exploits are currently available. However, given the high CVSS score (8.8) and ease of exploitation, patches should be deployed promptly.

What versions of Splunk Secure Gateway are affected by CVE-2026-20251?

Splunk Secure Gateway versions 3.10.0 through 3.10.5 are vulnerable. Additionally, versions 3.9.0–3.9.19 and 3.8.0–3.8.66 are affected. Update to 3.10.6, 3.9.20, or 3.8.67 respectively.

How do I check if my server is vulnerable to CVE-2026-20251?

Run: splunk show forward-server | grep -i version or cat /opt/splunk/etc/apps/splunk_secure_gateway/default/app.conf | grep version. If the version is below 3.10.6 (or 3.9.20 / 3.8.67 for older branches), your installation is vulnerable.

Does Defensia detect CVE-2026-20251?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Splunk Secure Gateway is installed on a monitored server, CVE-2026-20251 will appear in your dashboard with remediation steps.

Related Python CVEs

CVE-2026-25632CVSS 10EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. This vulnerability is fixed in 0.16.1.
CVE-2026-28505CVSS 10Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed eval() for notification text templates. The sandbox attempts to restrict callable names by inspecting code.co_names of the compiled code object. However, co_names only contains names from the outer code object. When a lambda expression is used, it creates a nested code object whose attribute accesses are stored in code.co_consts, NOT in code.co_names. The sandbox never inspects nested code objects. This issue has been patched in version 2.17.0.
CVE-2026-34938CVSS 10PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving arbitrary OS command execution on the host. This issue has been patched in version 1.5.90.
CVE-2026-33054CVSS 10Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI stream payload to arbitrarily target files on the disk under the standard file-based runtime backend. This can result in application denial of service (via crash loops when reading non-msgpack target files as configurations), or arbitrary file manipulation. This vulnerability heavily exposes systems hosted utilizing FileStateSessionBackend. Unauthorized malicious actors could interact with arbitrary payloads overwriting or explicitly removing underlying service resources natively outside the application bounds. This issue has been fixed in version 1.2.3.
CVE-2026-9135CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated ToolGuard Python files. Attackers can embed malicious Python code in these unvalidated dynamic fields, which are persisted in Flow.data and later executed server-side when a guarded tool is invoked through the ToolGuard runtime. This allows authenticated users with flow creation privileges to achieve arbitrary Python code execution on the backend despite custom component restrictions. The vulnerability can be escalated through cross-tenant flow manipulation via the agentic MCP update_flow_component_field tool, which accepts attacker-controlled user_id parameters, enabling attackers to inject malicious code into victim users' flows. When combined with publicly accessible flows and specific misconfigurations (AUTO_LOGIN=true, NEW_USER_IS_ACTIVE=true), the attack can be conducted with reduced authentication requirements.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-20251. Free for 1 server.

Get started free