CVE-2026-45392 Details
Description
DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an authenticated user who is tricked into visiting a crafted URL and interacting with the page.
A SQL injection vulnerability has been identified in Cribl Stream versions prior to 4.17.1. This issue resides within the REST Collector Source, where the application improperly validates user input, allowing for the manipulation of SQL queries. As a result, an attacker could potentially execute arbitrary SQL commands, leading to unauthorized data access or modification.
Users are advised to upgrade to Cribl Stream version 4.17.1, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.cribl.io/stream/release-notes/release-v4171#security-fixes | Cribl | Release NotesVendor |
| https://trust.cribl.io/notifications | Cribl | Mailing ListVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Cribl |
Affected Products
| Product | Versions |
|---|---|
| Cribl Stream | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cribl |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | Cribl |
| May 15, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | Cribl |
Volerion