CVE-2026-56747: Cribl Stream
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.
Affected products
- Cribl Cribl Stream: before 4.18.2 (fixed in 4.18.2)
Published 2026-07-27. Last modified 2026-08-20.