Junglewise Threat Intelligence

CVE-2026-45392: Cribl Stream DOM-based XSS in web interface

CVE-2026-45392 · Severity: high · CVSS 8.7 · Published 2026-05-12

Technologies: Cribl Stream. Vendors: Cribl.

Executive brief

Cribl Stream is a data processing engine used to route and transform security and observability data. A vulnerability in its web interface could allow an attacker to execute malicious scripts in the browser of a logged-in user. If an administrator is tricked into clicking a malicious link, the attacker could potentially gain unauthorized access to the system, modify configurations, or steal sensitive session information.

Technical details

A DOM-based cross-site scripting (XSS) vulnerability exists in Cribl Stream versions prior to 4.17.1. The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject malicious scripts into the Document Object Model (DOM). An attacker can exploit this by convincing an authenticated user to visit a specially crafted URL and interact with the page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's session, which can lead to session hijacking or unauthorized administrative actions. The vendor has addressed this in version 4.17.1.

Affected products

  • Cribl Stream before 4.17.1

Timeline

  • 2026-04-22: patched: Cribl Stream 4.17.1 released with security fixes.
  • 2026-05-12: advisory: CVE-2026-45392 published.

References

Related threats