CVE-2026-56748
Received Received - Intake

Improper Symbolic Link Validation in Cribl Stream

Vulnerability report for CVE-2026-56748, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: af879a92-7297-456a-bb0e-905ac6c64bdc

Description

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-28
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cribl stream 4.18.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper validation of symbolic links in the Pack Git import feature of Cribl Stream versions before 4.18.2. A remote authenticated attacker with specific permissions can exploit this by using a crafted Git repository containing a symbolic link in the pack's functions directory to execute arbitrary code as the Cribl server process.

Detection Guidance

Detecting this vulnerability requires checking if your Cribl Stream version is before 4.18.2. Use commands like 'cribl version' or check the installed package version via your system's package manager. Inspect Git repositories used in Pack imports for symbolic links in the functions directory.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary code on the Cribl server, potentially leading to unauthorized access, data breaches, or disruption of services. It requires the attacker to have Pack import and pipeline preview permissions, which limits the scope but still poses a significant risk.

Compliance Impact

This vulnerability allows remote authenticated attackers with specific permissions to execute arbitrary code on the Cribl server process. This could lead to unauthorized access, data exfiltration, or manipulation of sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data privacy).

Mitigation Strategies

Upgrade Cribl Stream to version 4.18.2 or later immediately. Remove or restrict Pack import and pipeline preview permissions for users until the upgrade is complete. Review and audit all Pack Git repositories for suspicious symbolic links.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56748. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart