CVE-2026-40050 Details
Description
CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability exists in a specific cluster API endpoint that, if exposed, allows a remote attacker to read arbitrary files from the server filesystem without authentication. Next-Gen SIEM customers are not affected and do not need to take any action. CrowdStrike mitigated the vulnerability for LogScale SaaS customers by deploying network-layer blocks to all clusters on April 7, 2026. We have proactively reviewed all log data and there is no evidence of exploitation. LogScale Self-hosted customers should upgrade to a patched version immediately to remediate the vulnerability. CrowdStrike identified this vulnerability during continuous and ongoing product testing.
A critical unauthenticated path traversal vulnerability has been identified in CrowdStrike LogScale self-hosted versions 1.224.0 through 1.234.0, including LogScale Self-Hosted LTS versions 1.228.0 and 1.228.1. This vulnerability exists in a specific cluster API endpoint, allowing remote attackers to read arbitrary files from the server filesystem without authentication. CrowdStrike has no evidence of exploitation of this vulnerability in the wild.
CrowdStrike has released patched versions to address this vulnerability. Self-hosted customers should upgrade to version 1.235.1 or later, 1.234.1 or later, 1.233.1 or later, or 1.228.2 (LTS) or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.crowdstrike.com/en-us/security-advisories/cve-2026-40050/ | CrowdStrike Holdings, Inc. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CrowdStrike Holdings, Inc. |
| CWE-306 | Missing Authentication for Critical Function | CrowdStrike Holdings, Inc. |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CrowdStrike Holdings, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | CrowdStrike Holdings, Inc. |