CrowdStrike LogScale Vulnerability Lets Remote Attackers Read Arbitrary Server Files
ID: 95690412-814c-5274-90d0-7c9604315259
STIX ID: report--95690412-814c-5274-90d0-7c9604315259
Feed Name: Cyber Press
CrowdStrike disclosed CVE-2026-40050, a critical (CVSS 9.8) unauthenticated path traversal in LogScale self-hosted clusters allowing remote arbitrary file access; affected self-hosted versions include 1.224.0–1.234.0 and LTS 1.228.0/1, while patched releases (e.g., 1.235.1, 1.234.1, 1.233.1, LTS 1.228.2+) are available. CrowdStrike reports no evidence of active exploitation, notes SaaS customers received network-layer protections, and urges immediate patching and network restrictions to prevent exposure of sensitive files and credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
