PT-2026-65104 · Cribl · Cribl Stream

CVE-2026-56747

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cribl Stream versions prior to 4.18.2
Description Improper control of code generation within the JSON Pointer-to-accessor compiler allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server. This is achieved by providing a crafted database connection identifier or pack configuration value.
Recommendations Update to version 4.18.2 or later.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56747

Affected Products

Cribl Stream