logo

Critical bug in CrowdStrike LogScale let attackers access files

ID: d222de07-4305-59af-a4d6-c419bd52ff70

STIX ID: report--d222de07-4305-59af-a4d6-c419bd52ff70

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-04-26

Date Updated: 2026-05-05

Author: Pierluigi Paganini

...
...

**CrowdStrike patched CVE-2026-40050**, a critical unauthenticated path traversal in LogScale self-hosted that could allow remote attackers to read arbitrary files; CrowdStrike says the flaw was found internally, has been mitigated for SaaS customers, and there are no known in-the-wild exploits, but self-hosted customers must urgently apply updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.