CVE-2026-56748 Details
Description
Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.
A vulnerability in Cribl Stream versions prior to 4.18.2 exists in the Pack Git import feature. It allows remote authenticated attackers with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process. This is achieved by using a crafted Git repository that includes a symbolic link in the pack's functions directory, which is not properly validated. The vulnerability takes advantage of the way symbolic links are handled during the import process, potentially leading to unintended file path resolutions and execution of malicious code.
Users are advised to upgrade Cribl Stream to version 4.18.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.cribl.io/stream/release-notes/release-v4182/#security-fixes | Cribl | Release Notes |
| https://trust.cribl.io/notifications | Cribl | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-61 | UNIX Symbolic Link (Symlink) Following | Cribl |
Affected Products
| Product | Versions |
|---|---|
| cribl cribl stream | < 4.18.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 20, 2026 | Initial Analysis | [email protected] |
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | Cribl |