Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026
Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
CVE-2026-56748
Description
Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.
Affected products
1Patches
Vulnerability mechanics
References
2- trust.cribl.io/notificationsmitrevendor-advisory
- docs.cribl.io/stream/release-notes/release-v4182/mitrerelease-notes
News mentions
0No linked articles in our index yet.