SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-56747

HIGH · CVSS 8.8 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The vulnerability affects the Cribl Stream application, specifically its JSON Pointer-to-accessor compiler, allowing remote authenticated attackers with edit privileges to execute arbitrary JavaScript on the server through a manipulated database connection identifier or pack configuration value. This could lead to unauthorized access and potential compromise of the server's integrity. Organizations using Cribl Stream prior to version 4.18.2 should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-56747
Severity
HIGH
CVSS
8.8
EPSS
0.37%
Java

Original NVD Description

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.

Related CVEs

Other vulnerabilities affecting the same vendor(s)