CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server
ID: b72e39cb-5208-5d14-9d6e-f0c0783e6d14
STIX ID: report--b72e39cb-5208-5d14-9d6e-f0c0783e6d14
Feed Name: cybersecurityNews.com
CrowdStrike disclosed a critical unauthenticated path-traversal flaw (CVE-2026-40050, CVSS 9.8) in LogScale Self-Hosted (affecting GA 1.224.0–1.234.0 and LTS 1.228.0/1) that could let remote attackers read arbitrary filesystem files; CrowdStrike applied network-layer blocks for SaaS clusters, released patched builds (e.g., 1.235.1, 1.234.1, 1.233.1, 1.228.2 LTS), reported no evidence of exploitation, and urges self-hosted customers to upgrade and review for possible prior access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
