Live
eineurope/
Home/Global/Topic · Critical CrowdStrike LogScale vulnerability disclosed
Global1d ago

Critical CrowdStrike LogScale vulnerability disclosed

CrowdStrike disclosed a critical path traversal flaw in its LogScale software that allows attackers to read arbitrary files from server filesystems.

Sources
1 verified
Location
Updated
Monday, 27 April 2026 at 05:00 UTC
No media · text-only dispatch
Synthesis · 1 sources
CrowdStrike has disclosed CVE-2026-40050, a critical unauthenticated path traversal vulnerability in its LogScale self-hosted deployments. The flaw, discovered through internal testing, allows remote attackers to read arbitrary files from the server's filesystem via a specific cluster API endpoint. While SaaS customers were protected via network-layer mitigations on April 7, self-hosted customers require immediate patching. No active exploitation has been observed, but such defensive platforms are high-value targets as compromise can undermine detection and enable lateral movement.
e/eineurope · topic · T-08826