


Perceptive Security
SOC/SIEM Consultancy

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability on…
Published:
20 april 2026 om 22:00:00
Alert date:
21 april 2026 om 18:10:28
Source:
nvd.nist.gov
Security Tools
CrowdStrike released security updates for a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. The vulnerability exists in a cluster API endpoint that allows remote attackers to read arbitrary files without authentication. Next-Gen SIEM customers are not affected. CrowdStrike deployed network-layer blocks for SaaS customers on April 7, 2026, and found no evidence of exploitation. Self-hosted customers must upgrade immediately. The vulnerability was discovered during internal product testing.
Technical details
Mitigation steps:
Affected products:
CrowdStrike LogScale
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40050
https://www.crowdstrike.com/en-us/security-advisories/cve-2026-40050/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
