logo

CrowdStrike Issues Critical Alert: LogScale Vulnerability Allows Unauthenticated File Access

ID: d79092db-6a5d-56ac-890b-b81cbfe71977

STIX ID: report--d79092db-6a5d-56ac-890b-b81cbfe71977

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Ddos

...
...

CrowdStrike disclosed a critical path traversal and missing-authentication vulnerability (CVE-2026-40050, CVSS 9.8) in LogScale that allows unauthenticated remote attackers to read arbitrary files from self-hosted servers. SaaS customers were mitigated via network-layer blocks on April 7, 2026; self-hosted users are urged to upgrade immediately to the listed patched versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.