Vulnerabilities · 88 days ago
A config helper that accepts admin input can become an OS command launcher on the Splunk host, so patching the add-on is about protecting the underlying server, not just the toolkit. In Splunk AI Toolkit, that path exists in the btool helper and gives authenticated admins host-level command execution.
Splunk fixed CVE-2026-20266 in AI Toolkit 5.7.4. Atlassian also issued a broad dependency round across Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, and Jira Service Management, with dozens of flaws landing in shared third-party components such as Axios, Apache Tomcat, and Netty.
The operational risk is broader than one feature or one CVE. If your products inherit shared libraries, the patch may arrive as a parent product update, and the real exposure sits wherever admin-facing helpers pass user-controlled values into shell commands.
CVEs in this update
9 CVEs
Across Bitbucket, Confluence, Secure Connect Gateway, and related packages.
4 critical · 3 high · 2 medium · 0 low
0 in CISA KEV · 4 with EPSS above 1%
Highest severity: CVE-2026-41293 · 9.8 CRITICAL
Highest EPSS: CVE-2026-40175 · 1.9%
2 sources covering this story
Risolte vulnerabilità in prodotti Atlassian
Rilasciati aggiornamenti di sicurezza per risolvere alcune vulnerabilità di cui 8 con gravità “critica” e 24 con gravità “alta” presenti nei prodotti Bamboo, Jira, Bitbucket, Confluence e Crowd, nelle versioni Data Center e Server di Atlassian.
Atlassian, Splunk Patch Critical Vulnerabilities
Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies.
Part of the PlainSec briefing for 2026-06-19