Path Traversal Vulnerability in LogScale from CrowdStrike
CVE-2026-40050
Key Information:
- Vendor
Crowdstrike
- Status
- Vendor
- CVE Published:
- 21 April 2026
Badges
What is CVE-2026-40050?
CVE-2026-40050 is a critical path traversal vulnerability found in LogScale, a product provided by CrowdStrike that is designed for managing large-scale log data and analytics. This vulnerability enables an unauthenticated remote attacker to access arbitrary files stored on the server's filesystem through a specific API endpoint. Such unauthorized access can lead to significant data exposure, potentially comprising sensitive information stored on the affected system. This vulnerability is particularly concerning for organizations that utilize self-hosted versions of LogScale, as it presents risks related to data privacy and integrity.
Potential impact of CVE-2026-40050
-
Unauthorized Data Access: Exploitation of this vulnerability allows attackers to read sensitive files without authentication, which can lead to unauthorized access to confidential information, including configuration files and user data.
-
Compromise of System Integrity: By accessing arbitrary files, threat actors could obtain critical information that may help them manipulate the system or escalate their privileges, thereby compromising the integrity of the entire application or server.
-
Increased Risk of Future Attacks: The exposure of sensitive information can facilitate further attacks against an organization, including phishing campaigns or targeted exploits that leverage the information gained through this vulnerability.
Affected Version(s)
LogScale Self-Hosted 1.224.0 <= 1.235.0
News Articles
CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server - IT Security News
CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication....
CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server
CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server's filesystem without authentication.
References
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 📰
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved
