Junglewise Threat Intelligence

CVE-2026-56748: Cribl Stream remote code execution via Pack Git import symlink following

CVE-2026-56748 · Severity: high · CVSS 8.8 · Published 2026-07-27

Technologies: Cribl Stream. Vendors: Cribl.

Executive brief

Cribl Stream, a data processing engine used to route and transform machine data, is vulnerable to a security flaw in its Pack Git import feature. An attacker with specific permissions could use a specially crafted Git repository to execute malicious code on the server. This could lead to a complete takeover of the Cribl server, potentially resulting in data theft, service disruption, or unauthorized access to sensitive corporate data flows.

Technical details

A symbolic link (symlink) following vulnerability exists in the Pack Git import feature of Cribl Stream. The root cause is improper validation of symlinks within a pack's directory structure, specifically within the functions directory. An authenticated remote attacker with 'Pack import' and 'pipeline preview' permissions can exploit this by importing a crafted Git repository containing malicious symlinks. Successful exploitation allows the attacker to achieve arbitrary code execution (RCE) with the privileges of the Cribl server process. The issue is resolved in Cribl Stream version 4.18.2, which now blocks packs containing symlinks during the import process.

Affected products

  • Cribl Cribl Stream before 4.18.2

Timeline

  • 2026-06-24: patched: Release date of version 4.18.2
  • 2026-07-27: advisory: CVE published

References

Related threats