CVE-2026-20251·Python vulnerability
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could perform a Remote Code Execution (RCE) through the Splunk Secure Gateway app.<br><br>The Remote Code Execution is possible because of unsafe deserialization of App Key Value Store (KV Store) data through the ‘jsonpickle’ Python library, which reconstructs arbitrary Python objects from specially crafted JavaScript Object Notation (JSON) without adequate validation.
- Severity
- high
- Software
- Python
- Fixed in
- 3.10.6
- Published
- 2026-06-10
Affected versions
From: 3.10.0
Until: 3.10.6
Fixed in: 3.10.6
How to fix this CVE
Update Splunk Secure Gateway to version 3.10.6 or later to remediate unsafe deserialization vulnerabilities in the KV Store integration. This vulnerability allows low-privileged users to execute arbitrary Python code by exploiting improper object reconstruction via the jsonpickle library. Immediate patching is critical as this affects all deployments regardless of role configuration.
sudo dnf update python3Defensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST requests to /api/kvstore/app_kv_store with JSON payloads containing __reduce__, __setstate__, or __dict__ attributes; or observation of unexpected Python subprocess/exec calls originating from splunkd processes handling KV Store operationsWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block or sanitize JSON payloads sent to Splunk Secure Gateway KV Store endpoints that contain Python object serialization markers (__reduce__, __setstate__, __dict__, __class__). Implement strict input validation on all KV Store write operations and enforce JSON schema validation to reject non-primitive objects.How to check if you are affected
- Check installed Splunk Secure Gateway version: splunk show forward-server | grep version or review /opt/splunk/etc/apps/splunk_secure_gateway/default/app.conf
- Verify jsonpickle library presence and version: python3 -m pip show jsonpickle or find /opt/splunk -name 'jsonpickle*'
- Search KV Store transaction logs for suspicious JSON deserialization patterns: grep -r '__reduce__\|__setstate__\|__dict__' /opt/splunk/var/log/
- Confirm remediation by re-checking Splunk Secure Gateway version matches 3.10.6+ and comparing against advisory baseline
FAQ
What is CVE-2026-20251?
This is a remote code execution flaw in Splunk Secure Gateway caused by unsafe deserialization of Python objects from KV Store data. Attackers can craft malicious JSON payloads that reconstruct arbitrary Python objects, allowing code execution with the privileges of the Splunk process.
Is CVE-2026-20251 being actively exploited?
No active exploitation has been reported in the wild according to CISA KEV data, and no public exploits are currently available. However, given the high CVSS score (8.8) and ease of exploitation, patches should be deployed promptly.
What versions of Splunk Secure Gateway are affected by CVE-2026-20251?
Splunk Secure Gateway versions 3.10.0 through 3.10.5 are vulnerable. Additionally, versions 3.9.0–3.9.19 and 3.8.0–3.8.66 are affected. Update to 3.10.6, 3.9.20, or 3.8.67 respectively.
How do I check if my server is vulnerable to CVE-2026-20251?
Run: splunk show forward-server | grep -i version or cat /opt/splunk/etc/apps/splunk_secure_gateway/default/app.conf | grep version. If the version is below 3.10.6 (or 3.9.20 / 3.8.67 for older branches), your installation is vulnerable.
Does Defensia detect CVE-2026-20251?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Splunk Secure Gateway is installed on a monitored server, CVE-2026-20251 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-20251. Free for 1 server.
Get started free