What is CVE-2026-56747?
An improper control of code generation vulnerability exists in the JSON Pointer-to-accessor compiler of Cribl Stream. This flaw allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server by using a crafted database connection identifier or pack configuration value. Users must urgently upgrade Cribl Stream to version 4.18.2 or later.
Azərbaycanca: Cribl Stream məhsulunda JSON Pointer-to-accessor kompilyatorunda kod generasiyasına nəzarətin düzgün olmaması zəifliyi aşkarlanıb. Bu boşluq, redaktə hüquqlarına malik autentifikasiya olunmuş uzaq təcavüzkara xüsusi hazırlanmış verilənlər bazası bağlantı identifikatoru və ya paket konfiqurasiya dəyəri vasitəsilə serverdə özbaşına JavaScript kodu icra etməyə imkan verir. Cribl Stream istifadəçiləri təcili olaraq 4.18.2 və daha yuxarı versiyalara yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What privileges must an attacker have to exploit CVE-2026-56747?
The attacker must be a remote authenticated user with edit privileges.
To which version should Cribl Stream be upgraded to fix CVE-2026-56747?
Cribl Stream must be urgently upgraded to version 4.18.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.