CVE-2026-40050Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability exists in a specific cluster API endpoint that, if exposed, allows a remote attacker to read arbitrary files from the server filesystem without authentication. Next-Gen SIEM customers are not affected and do not need to take any action. CrowdStrike mitigated the vulnerability for LogScale SaaS customers by deploying network-layer blocks to all clusters on April 7, 2026. We have proactively reviewed all log data and there is no evidence of exploitation. LogScale Self-hosted customers should upgrade to a patched version immediately to remediate the vulnerability. CrowdStrike identified this vulnerability during continuous and ongoing product testing.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-306

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 37 mentions across 10 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 20 signals
  • Technical details provided in 33 signals
  • Disclosure: 17 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 12 mentions (2026-04-27); latest day: 1
  • 37 total mentions across 10 days

Deep dive

Activity timeline37 mentions / 10d
036912Mentions · 2026-04-21: 1Mentions · 2026-04-22: 8Mentions · 2026-04-23: 4Mentions · 2026-04-24: 2Mentions · 2026-04-26: 6Mentions · 2026-04-27: 12Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-04: 1PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-27: 1Exploit Tool / Code · 2026-04-23: 1Patch / Workaround · 2026-04-22: 5Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-26: 6Patch / Workaround · 2026-04-27: 6Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 7Technical Details · 2026-04-23: 4Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 6Technical Details · 2026-04-27: 10Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-04: 104-2104-2204-2304-2404-2604-2704-2904-3005-0105-04
Signal classification4 categories
Disclosure
1745.9%
Patch
1745.9%
General
25.4%
PoC
12.7%
Referenced assets26 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-04-228
Disclosure5Patch3
2026-04-234
Disclosure2Patch1PoC1
2026-04-242
General1Patch1
2026-04-266
Disclosure1Patch5
2026-04-2712
Disclosure5General1Patch6
2026-04-291
Disclosure1
2026-04-301
Patch1
2026-05-011
Disclosure1
2026-05-041
Disclosure1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Disclosure

    ⚠️ CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Files from Server Source: https://cybersecuritynews.com/crowdstrike-logscale-vulnerability/ An urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication. The vulnerability resides in a specific cluster API endpoint within CrowdStrike LogScale. If this endpoint is exposed, a remote attacker can leverage it to traverse the server’s directory structure and access sensitive files without needing credentials. #cybersecuritynews

    Post summary

    The advisory discloses a critical unauthenticated path‑traversal flaw (CVE‑2026‑40050) in CrowdStrike LogScale that permits remote attackers to read arbitrary server files, with no mention of PoC, exploit code, or active exploitation.

    69122838531.2K
    67.1K followersView on X
  • yousukezan@yousukezan
    Disclosure

    CrowdStrikeのLogScaleに重大脆弱性が見つかり、認証不要でサーバ内の機密ファイルが読み取られる恐れが判明した。自社運用環境では特に深刻な影響が懸念される。 問題はCVE-2026-40050で、CVSS 9.8のクリティカルに分類される。クラスタAPIのエンドポイントに存在するパストラバーサルと認証不備の組み合わせにより、攻撃者はログイン不要で任意ファイルを取得できる。これにより設定ファイルやログ、認証情報などが漏洩する可能性がある。現時点で実際の悪用は確認されていないが、影響範囲は広い。SaaS版については2026年4月7日にネットワークレベルで遮断措置が講じられている一方、自社ホスト環境が主なリスク対象となる。 影響を受けるのはLogScale 1.224.0〜1.234.0およびLTS 1.228.0、1.228.1で、Next-Gen SIEMには影響しない。利用者には修正版への即時更新が強く求められている。 https://securityonline.info/crowdstrike-logscale-vulnerability-cve-2026-40050-path-traversal/

    Post summary

    CrowdStrike LogScale is affected by CVE-2026-40050, a critical path‑traversal flaw allowing unauthenticated file reads; no active exploitation has been reported yet, and users are urged to apply the patch immediately.

    02111174211.8K
    14.4K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Patch

    CrowdStrike fixed CVE-2026-40050 in LogScale self-hosted, detailing an unauthenticated path traversal that could let attackers read arbitrary server files, with SaaS mitigated and Next-Gen SIEM unaffected. https://securityaffairs.com/191343/hacking/critical-bug-in-crowdstrike-logscale-let-attackers-access-files.html

    Post summary

    The post announces that CrowdStrike has released a patch for CVE-2026‑40050, a path traversal flaw allowing unauthenticated file read, and provides limited technical details about the issue.

    1701821.8K
    22.4K followersView on X
  • CRYPTO ASSET RECOVERY BUREAU 🧑🏼‍💻@Recovery_io
    Disclosure

    CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Files from Server X Source: http://cybersecuritynews.com/crowdstrike- IO... An urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform #cybersecuritynews https://t.co/jOrWAhGJaN

    Post summary

    An advisory reports a critical unauthenticated path‑traversal vulnerability (CVE‑2026‑40050) in CrowdStrike LogScale that could allow remote attackers to read any file on the server.

    09090194
    4.0K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - CrowdStrike LogScale path traversal (CVE-2026-40050) An unauthenticated path traversal flaw allows remote attackers to read arbitrary files from the server via an exposed API endpoint. 👉 Self-hosted customers must upgrade immediately | SaaS already mitigated

    Post summary

    CrowdStrike LogScale has a critical unauthenticated path traversal vulnerability that allows attackers to read any server files via the API; self‑hosted customers must apply the immediate patch, while SaaS users are already protected.

    0004096
    44 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Patch

    🚨 Critical CrowdStrike LogScale Flaw Allows Unauthenticated File Access fixes CVE-2026-40050 in LogScale → Unauthenticated path traversal → Attackers can read arbitrary server files → Affects self-hosted deployments ⚠️ SaaS / Next-Gen SIEM NOT affected 💡 Why this matters: Log platforms = central visibility layer Compromise = access to logs, configs, credentials No active exploitation reported yet — but risk is high 🔧 Action: Patch immediately https://securityaffairs.com/191343/hacking/critical-bug-in-crowdstrike-logscale-let-attackers-access-files.html

    Post summary

    CVE-2026-40050 in CrowdStrike LogScale permits unauthenticated path traversal, enabling attackers to read any server file on self-hosted deployments. The vulnerability is not actively exploited yet but is critical; immediate patching is required.

    00031488
    16.1K followersView on X
  • Elusive@ElusivePrivacy
    Patch

    🛡️ Two security vendors patched serious flaws in their own products this week. CrowdStrike: CVE-2026-40050, a critical unauthenticated path traversal in LogScale — remote attackers could read arbitrary server files. Self-hosted customers need to update. Tenable: CVE-2026-33694, a high-severity Nessus flaw on Windows allowing arbitrary file deletion and code execution with elevated privileges. 📄 Source: SecurityWeek 👉 Follow @VulnerabilityNw — patch tracking on our Telegram → http://t.me/VulnerabilityNews

    Post summary

    Both CrowdStrike LogScale and Tenable Nessus have released patches for critical CVEs; users are advised to update immediately.

    02020172
    185 followersView on X
  • Zyberwalls@ZyberWallS
    General

    Critical flaw in CrowdStrike LogScale (CVE-2026-40050) lets attackers read files without login on self-hosted setups. Read the full analysis: https://www.zyberwalls.com/2026/04/crowdstrike-logscale-cve-2026-40050-path-traversal.html #CyberSecurity #ZeroDay #CrowdStrike #ThreatIntel #InfoSec

    Post summary

    The post alerts to a critical path‑traversal flaw in CrowdStrike LogScale that permits unauthenticated file reads, but it offers no PoC, exploit details, patch information, or evidence of active exploitation.

    01020175
    20 followersView on X
  • CiberBaur@BotBauR
    Patch

    Acaba de confirmarse: CrowdStrike parcheó una vulnerabilidad crítica en LogScale, CVE-2026-40050, que permite a atacantes acceder a archivos sin autenticación a través de una vulnerabilidad de travesía de ruta. CrowdStrike LogScale, utilizado por muchas empresas para la gestión de logs, tuvo una falla que podría haber permitido a atacantes leer archivos arbitrarios del servidor. La vulnerabilidad, identificada como CVE-2026-40050, fue parcheada recientemente. El impacto de esta vulnerabilidad podría ser significativo, ya que podría permitir a atacantes acceder a información confidencial, como claves de acceso o datos sensibles. Afortunadamente, no se han reportado exploits in-the-wild públicos al momento del artículo. CrowdStrike ya ha parcheado la vulnerabilidad en versiones superiores a la versión afectada. Si estás utilizando LogScale, es crucial que actualices a la versión más reciente para evitar posibles ataques. ¿Estás en riesgo? Revisa esto: actualiza LogScale a la versión más reciente y verifica los logs de acceso para detectar cualquier actividad sospechosa. https://securityaffairs.com/191343/hacking/critical-bug-in-crowdstrike-logscale-let-attackers-access-files.html

    Post summary

    CrowdStrike has released a patch for CVE‑2026‑40050, a path‑traversal flaw in LogScale that could let attackers read arbitrary files; no public in‑the‑wild exploits have been reported.

    0102059
    399 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة في منصة CrowdStrike LogScale تسمح للمهاجمين عن بعد بقراءة ملفات عشوائية من الخادم أصدرت CrowdStrike تحذيرًا أمنيًا عاجلاً بشأن ثغرة خطيرة في تجاوز المسار غير المصادق (CVE-2026-40050) في منصة LogScale الخاصة بها. يمكن للمهاجم عن بعد استغلال هذه الثغرة لقراءة ملفات عشوائية من الخادم. تؤثر هذه الثغرة على منصة LogScale، وقد حذرت CrowdStrike من ضرورة اتخاذ إجراءات فورية لتجنب المخاطر. — يُنصح بتحديث البرنامج وتفعيل التصحيحات الأمنية. 🔗 للمزيد: https://cybersecuritynews.com/crowdstrike-logscale-vulnerability/

    Post summary

    CVE‑2026‑40050 is a path‑traversal vulnerability in CrowdStrike LogScale that lets remote attackers read arbitrary files; the vendor issued an urgent advisory urging users to apply the available patch.

    00030800
    268 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    CrowdStrikeがLogScaleにおける重大(Critical)な脆弱性を修正。CVE-2026-40050はCVSSスコア9.8で、パストラバーサルと認証欠如の合わせ技。クラスタAPIエンドポイントから認証無しでサーバ上の任期ファイルを読み取れる。修正版提供済み。 https://securityonline.info/crowdstrike-logscale-vulnerability-cve-2026-40050-path-traversal/

    Post summary

    CrowdStrike has released a fix for CVE‑2026‑40050, a critical path‑traversal plus auth‑bypass flaw in LogScale that allowed unauthenticated file reads.

    01011930
    7.4K followersView on X
  • Zyberwalls@ZyberWallS
    Disclosure

    SIEM blind spot. Critical risk. CVE-2026-40050 in CrowdStrike LogScale lets attackers read any file — no auth needed. Analysis: https://www.zyberwalls.com/2026/04/crowdstrike-logscale-cve-2026-40050-path-traversal.html #CyberSecurity #ZeroDay #ThreatIntel #InfoSec

    Post summary

    The message announces a newly disclosed path‑traversal flaw (CVE‑2026‑40050) in CrowdStrike LogScale that permits unauthenticated reading of any file.

    01010139
    20 followersView on X
  • CSIRT TELCONET@CSIRT_Telconet
    Disclosure

    CrowdStrike ha detectado una vulnerabilidad crítica de path traversal (CVE-2026-40050) en LogScale, que permite a atacantes remotos acceder a archivos sin autenticación a través de un endpoint API expuesto. Mas información: https://csirt.telconet.net/comunicacion/boletines-servicios/vulnerabilidad-critica-de-path-traversal-sin-autenticacion-en-crowdstrike-logscale/ https://t.co/0rezicAH1c

    Post summary

    CrowdStrike ha detectado una vulnerabilidad crítica de path traversal (CVE-2026-40050) en LogScale que permite a atacantes remotos acceder a archivos sin autenticación a través de un endpoint API expuesto.

    01010166
    827 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    CrowdStrike LogScale の脆弱性 CVE-2026-40050 が FIX:システム・ファイルへの不正アクセスの恐れ https://iototsecnews.jp/2026/04/22/crowdstrike-logscale-vulnerability-allows-remote-attackers-to-read-arbitrary-files-from-server/ CrowdStrike のログ管理プラットフォーム LogScale における、深刻なセキュリティ上の欠陥と対応について紹介する記事です。この問題の原因は、API エンドポイントにおける認証の欠如 (CWE-306) と、ファイルパスの処理に関する不備 (CWE-22) が組み合わさったことにあります。具体的には CVE-2026-40050 として識別されており、これらを悪用されると、外部の攻撃者がサーバ内の機密ファイルを自由に読み取ってしまう恐れがあります。ご利用のチームは、ご注意ください。#CrowdStrike #CVE202640050 #LogScale #Vulnerability

    Post summary

    The article announces CVE‑2026‑40050 in CrowdStrike LogScale, describes how missing auth and file‑path flaws enable arbitrary file reads, and notes the issue has been fixed without providing patch details.

    01000120
    485 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-40050 CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only req… https://www.cve.org/CVERecord?id=CVE-2026-40050

    Post summary

    CrowdStrike has released security updates to mitigate a critical unauthenticated path traversal vulnerability (CVE‑2026‑40050) in LogScale; no exploit details or active exploitation claims are present.

    00010187
    57.3K followersView on X
  • Threat ResQ™@ThreatResq
    Patch

    CrowdStrike fixed CVE-2026-40050 in LogScale self-hosted, a critical flaw allowing unauthenticated file access via path traversal. https://securityaffairs.com/191343/hacking/critical-bug-in-crowdstrike-logscale-let-attackers-access-files.html #CrowdStrike #CVE #LogScale #Vulnerability #Critical #PathTraversal #CyberSecurity #CybersecurityNews #ThreatResQ

    Post summary

    CrowdStrike has released a fix for CVE-2026-40050, which is a critical unauthenticated path traversal flaw in LogScale self-hosted allowing file access.

    0001061
    44 followersView on X
  • The420.in@The420in
    Disclosure

    Unauthenticated File Access Flaw in CrowdStrike LogScale: CVE-2026-40050 Raises Alarm Read more: https://the420.in/crowdstrike-logscale-vulnerability-cve-2026-40050-remote-file-theft-risk/ https://t.co/JMiaM0ASgq

    Post summary

    The tweet announces the discovery of an unauthenticated file‑access vulnerability (CVE‑2026‑40050) in CrowdStrike LogScale, highlighting the issue but providing no exploit details or patch information.

    0001074
    1.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『The vulnerability exists in a specific cluster API endpoint that, if exposed, allows a remote attacker to read arbitrary files from the server filesystem without authentication.』 CVE-2026-40050 — CrowdStrike LogScale Unauthenticated Path Traversal https://www.crowdstrike.com/en-us/security-advisories/cve-2026-40050/

    Post summary

    CrowdStrike disclosed CVE-2026-40050, an unauthenticated path traversal in LogScale that lets attackers read arbitrary files from the server filesystem via a cluster API endpoint.

    00010457
    6.8K followersView on X
  • Williams@williamscottt_
    Disclosure

    CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Files from Server X Source: http://cybersecuritynews.com/crowdstrike- IO... An urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform #cybersecuritynews https://t.co/FjHK8fY6MR

    Post summary

    An urgent advisory announces CVE‑2026‑40050, a critical unauthenticated path‑traversal flaw in CrowdStrike LogScale, but provides no PoC, exploit code, or patch details.

    0000065
    2.2K followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-40050: CrowdStrike LogScale Path Traversal Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04d-KCw0

    Post summary

    The post introduces CVE‑2026‑40050, a Path Traversal flaw in CrowdStrike LogScale, and offers guidance for businesses to respond—likely including patching or remediation steps.

    0000018
    29 followersView on X

Explore more