logo

CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server

ID: b72e39cb-5208-5d14-9d6e-f0c0783e6d14

STIX ID: report--b72e39cb-5208-5d14-9d6e-f0c0783e6d14

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Guru Baran

...
...

CrowdStrike disclosed a critical unauthenticated path-traversal flaw (CVE-2026-40050, CVSS 9.8) in LogScale Self-Hosted (affecting GA 1.224.0–1.234.0 and LTS 1.228.0/1) that could let remote attackers read arbitrary filesystem files; CrowdStrike applied network-layer blocks for SaaS clusters, released patched builds (e.g., 1.235.1, 1.234.1, 1.233.1, 1.228.2 LTS), reported no evidence of exploitation, and urges self-hosted customers to upgrade and review for possible prior access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.