Junglewise Threat Intelligence

CVE-2026-56747: Cribl Stream code injection in JSON Pointer-to-accessor compiler

CVE-2026-56747 · Severity: high · CVSS 8.8 · Published 2026-07-27

Technologies: Cribl Stream. Vendors: Cribl.

Executive brief

Cribl Stream, a data processing engine used to route and transform enterprise logs, contains a vulnerability that allows authorized users with editing permissions to run malicious code on the server. By providing specially crafted database connection details or configuration values, an attacker can gain full control over the server's operations. This could lead to the theft of sensitive data, disruption of data pipelines, or further unauthorized access to the corporate network.

Technical details

A code injection vulnerability (CWE-94) exists in the JSON Pointer-to-accessor compiler within Cribl Stream. The flaw is rooted in improper control of code generation when processing specific configuration inputs. A remote authenticated attacker with 'edit' privileges can exploit this by submitting a crafted database connection identifier or a malicious pack configuration value. Successful exploitation allows for arbitrary JavaScript execution in the context of the server process. The issue is resolved in Cribl Stream version 4.18.2.

Affected products

  • Cribl Stream before 4.18.2

Timeline

  • 2026-06-24: patched: Release date of version 4.18.2
  • 2026-07-27: disclosed: CVE published to NVD

References

Related threats