Junglewise Threat Intelligence

CVE-2026-45391: Cribl Edge command injection in Linux agent

CVE-2026-45391 · Severity: high · CVSS 7.8 · Published 2026-05-12

Vendors: Cribl.

Executive brief

Cribl Edge is a software agent used to collect and process observability data from Linux and Windows systems. A security vulnerability in the Linux version allows a person with basic access to the server to run unauthorized commands with the elevated privileges of the Cribl service. This could lead to a full system compromise, unauthorized data access, or disruption of data collection services.

Technical details

A command injection vulnerability exists in Cribl Edge for Linux versions 3.2.0 through 4.17.0. The flaw stems from improper neutralization of special elements used in OS commands (CWE-78) or improper input validation (CWE-20). A local, authenticated attacker with low privileges can exploit this vulnerability to execute arbitrary code in the context of the service account. While some automated assessments (CISA-ADP) suggest a network attack vector, the primary vendor advisory specifies a local attack vector. The issue is resolved in Cribl Edge version 4.17.1.

Affected products

  • Cribl Cribl Edge for Linux 3.2.0 through 4.17.0

Timeline

  • 2026-04-22: patched: Cribl Edge 4.17.1 released with security fixes.
  • 2026-05-12: disclosed: CVE-2026-45391 published.

References