Security Advisory

CVE-2026-56747

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-27 19:22:12
Last updated 2026-07-27 20:23:09
Assigner Cribl
CVSS score not scored
State PUBLISHED

Description

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.