Home / Security updates / CVE-2026-56747 Code Injection in JSON Pointer Processing Component in Cribl Stream
CVE-2026-56747 Code Injection in JSON Pointer Processing Component in Cribl Stream
Security updates detail rendered from /security-updates/upd_800b9b7f6e0ffde1.
Overview
| ID | upd_800b9b7f6e0ffde1 |
| Collection | Security Updates |
| Provider | TrustShare (TrustCloud / Kintent) |
| Company | Cribl |
| URL | - |
| Counts | - |
| Updated | - |
Raw record
| Field | Value |
|---|---|
| id | upd_800b9b7f6e0ffde1 |
| providerId | trustshare |
| organizationId | org_db5a178977544c0d |
| trustCenterId | tc_3321b21a903010d8 |
| title | CVE-2026-56747 Code Injection in JSON Pointer Processing Component in Cribl Stream |
| type | cve_publication |
| message | CVE-2026-56747: Code Injection in JSON Pointer Processing Component in Cribl Stream Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value. Severity: HIGH CVSS:3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) CVSS:4.0 8.7 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) Weakness: CWE-94 (Improper Control of Generation of Code) Affected: Cribl Stream versions before 4.18.2 Fixed in: Cribl Stream 4.18.2 Solution Upgrade Cribl Stream to v4.18.2 or higher. Upgrading fully resolves this vulnerability, and no additional mitigation is required. Mitigating Controls ● As a defense-in-depth best practice (independent of this CVE), audit accounts that hold Editor or Admin permissions and remove Editor access from any account that does not operationally require it (Settings > Members and Teams). ● Running Cribl Stream as a non-root user is also recommended; see https://docs.cribl.io/stream/deploy-runtime-user#configure-cribl-stream-for-non-root-user for guidance. References ● https://www.cve.org/CVERecord?id=CVE-2026-56747 ● https://docs.cribl.io/stream/release-notes/release-v4182#security-fixes Credit: Robert Lackey, Cribl Product Security |
| publishedAt | 2026-07-28 |
| gated | no |
| source | {
"field": "trustshare/notifications[]"
} |
| company | {
"id": "org_db5a178977544c0d",
"name": "Cribl",
"domains": [
"trust.cribl.io",
"cribl.io"
]
} |
| trust_center | {
"id": "tc_3321b21a903010d8",
"name": "Cribl",
"url": "https://trust.cribl.io",
"host": "trust.cribl.io"
} |
| provider | {
"id": "trustshare",
"name": "TrustShare (TrustCloud / Kintent)"
} |
| links | {
"self": "/v1/security-updates/upd_800b9b7f6e0ffde1",
"company": "/v1/companies/org_db5a178977544c0d",
"trust_center": "/v1/trust-centers/tc_3321b21a903010d8",
"provider": "/v1/providers/trustshare"
} |
Get this page with API
Rendered from the bluedoor Trust Centers API. Reproduce it:
GET https://api.bluedoor.sh/trust-centers/v1/security-updates/upd_800b9b7f6e0ffde1JSON