CrowdStrike Issues Critical Alert: LogScale Vulnerability Allows Unauthenticated File Access
ID: d79092db-6a5d-56ac-890b-b81cbfe71977
STIX ID: report--d79092db-6a5d-56ac-890b-b81cbfe71977
Feed Name: securityonline.info
Threat Score
CrowdStrike disclosed a critical path traversal and missing-authentication vulnerability (CVE-2026-40050, CVSS 9.8) in LogScale that allows unauthenticated remote attackers to read arbitrary files from self-hosted servers. SaaS customers were mitigated via network-layer blocks on April 7, 2026; self-hosted users are urged to upgrade immediately to the listed patched versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
