Path Traversal Vulnerability in LogScale from CrowdStrike
CVE-2026-40050

9.8CRITICAL

Key Information:

Vendor
CVE Published:
21 April 2026

Badges

📈 Trended📈 Score: 3,000👾 Exploit Exists📰 News Worthy

What is CVE-2026-40050?

CVE-2026-40050 is a critical path traversal vulnerability found in LogScale, a product provided by CrowdStrike that is designed for managing large-scale log data and analytics. This vulnerability enables an unauthenticated remote attacker to access arbitrary files stored on the server's filesystem through a specific API endpoint. Such unauthorized access can lead to significant data exposure, potentially comprising sensitive information stored on the affected system. This vulnerability is particularly concerning for organizations that utilize self-hosted versions of LogScale, as it presents risks related to data privacy and integrity.

Potential impact of CVE-2026-40050

  1. Unauthorized Data Access: Exploitation of this vulnerability allows attackers to read sensitive files without authentication, which can lead to unauthorized access to confidential information, including configuration files and user data.

  2. Compromise of System Integrity: By accessing arbitrary files, threat actors could obtain critical information that may help them manipulate the system or escalate their privileges, thereby compromising the integrity of the entire application or server.

  3. Increased Risk of Future Attacks: The exposure of sensitive information can facilitate further attacks against an organization, including phishing campaigns or targeted exploits that leverage the information gained through this vulnerability.

Affected Version(s)

LogScale Self-Hosted 1.224.0 <= 1.235.0

News Articles

CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server - IT Security News

CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication....

CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server

CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server's filesystem without authentication.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by Cybersecuritynews

  • Vulnerability published

  • Vulnerability Reserved

.