CVE-2026-56747: Cribl Stream

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.

Affected products

  • Cribl Cribl Stream: before 4.18.2 (fixed in 4.18.2)

Published 2026-07-27. Last modified 2026-08-20.