logo

CrowdStrike LogScale Vulnerability Lets Remote Attackers Read Arbitrary Server Files

ID: 95690412-814c-5274-90d0-7c9604315259

STIX ID: report--95690412-814c-5274-90d0-7c9604315259

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: AnuPriya

...
...

CrowdStrike disclosed CVE-2026-40050, a critical (CVSS 9.8) unauthenticated path traversal in LogScale self-hosted clusters allowing remote arbitrary file access; affected self-hosted versions include 1.224.0–1.234.0 and LTS 1.228.0/1, while patched releases (e.g., 1.235.1, 1.234.1, 1.233.1, LTS 1.228.2+) are available. CrowdStrike reports no evidence of active exploitation, notes SaaS customers received network-layer protections, and urges immediate patching and network restrictions to prevent exposure of sensitive files and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.