Junglewise Threat Intelligence

CVE-2026-45393: Cribl Edge critical security vulnerability

CVE-2026-45393 · Severity: critical · CVSS 9.8 · Published 2026-05-12

Vendors: Cribl.

Executive brief

Cribl Edge is a software agent used to collect and process observability data from distributed systems. A critical security vulnerability has been identified in versions prior to 4.17.1 that could allow an attacker to compromise the system. Organizations using this software should upgrade immediately to prevent potential unauthorized access to their data infrastructure or service disruptions.

Technical details

A critical vulnerability (CVE-2026-45393) exists in Cribl Edge for both Linux and Windows platforms. While specific technical details regarding the vulnerability class (e.g., RCE, Auth Bypass) are currently restricted behind the vendor's trust portal, the reported CVSS score of 9.8 suggests a network-reachable, unauthenticated attack vector with high impact on confidentiality, integrity, and availability. The issue is tracked internally by Cribl as CRIBL-39556 and CRIBL-39749. Users are advised to upgrade to Cribl Edge v4.17.1 or later to mitigate this risk.

Affected products

  • Cribl Edge versions prior to 4.17.1

Timeline

  • 2026-04-22: patched: On-prem binaries for v4.17.1 released
  • 2026-05-12: advisory: CVE published to NVD dataset

References