SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-56748

HIGH · CVSS 8.8 EPSS 0.58%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Pack Git import feature in Cribl Stream prior to version 4.18.2 is vulnerable due to improper validation of symbolic links, allowing remote authenticated attackers with specific permissions to execute arbitrary code as the Cribl server process. This vulnerability poses a significant risk to the integrity and security of the server, making it critical for organizations using affected versions to prioritize patching. Users with Pack import and pipeline preview permissions should be particularly vigilant in addressing this issue.

CVE
CVE-2026-56748
Severity
HIGH
CVSS
8.8
EPSS
0.58%

Original NVD Description

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)