Description
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.
Published: 2026-07-27
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the JSON Pointer-to-accessor compiler within Cribl Stream, where unsanitized input can be used to generate executable JavaScript. An attacker with authenticated edit privileges who supplies a crafted database connection identifier or pack configuration value can cause the server to run arbitrary JavaScript, compromising integrity, confidentiality, and potentially full system control.

Affected Systems

Cribl Stream versions prior to 4.18.2 are vulnerable. The issue applies to deployments that use the JSON Pointer processing component for database connections or pack configurations.

Risk and Exploitability

The CVSS score of 8.7 reflects high severity. Exploitation requires authenticated access with edit rights, limiting the attack surface to powerful accounts but still posing significant risk. The EPSS score indicates a very low exploitation probability of less than 1%, and the vulnerability is not listed in the CISA KEV catalog. No public exploit is documented, but the lack of a workaround means the recommended action is to apply the upgrade immediately.

Generated by OpenCVE AI on August 3, 2026 at 16:54 UTC.

Remediation

Vendor Solution

Upgrade Cribl Stream to v4.18.2 or higher. Upgrading fully resolves this vulnerability and no additional mitigation is required.


OpenCVE Recommended Actions

  • Apply the vendor patch and upgrade to Cribl Stream v4.18.2 or higher
  • If an upgrade is not immediately possible, restrict edit privileges on database connection identifiers and pack configuration values to only trusted administrators
  • Implement input validation for JSON Pointer expressions to prevent injection of executable JavaScript

Generated by OpenCVE AI on August 3, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Cribl
Cribl cribl Stream
Vendors & Products Cribl
Cribl cribl Stream

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.
Title Code Injection in JSON Pointer Processing Component in Cribl Stream
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cribl Cribl Stream
cve-icon MITRE

Status: PUBLISHED

Assigner: Cribl

Published:

Updated: 2026-07-27T20:23:09.438Z

Reserved: 2026-06-22T20:02:07.173Z

Link: CVE-2026-56747

cve-icon Vulnrichment

Updated: 2026-07-27T20:23:06.347Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-27T20:16:39.873

Modified: 2026-07-30T19:12:22.607

Link: CVE-2026-56747

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:00:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')