Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-56748

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 44.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-56748


Contact Us

Shodan ® - All rights reserved