CrowdStrike has disclosed a critical unauthenticated path traversal vulnerability (CVE-2026-40050) affecting self-hosted LogScale versions 1.224.0 through 1.235.0. The flaw resides in a specific cluster API endpoint that is externally reachable, allowing a remote, unauthenticated attacker to read arbitrary files from the server filesystem — requiring no privileges and no user interaction (CVSS AV:N/AC:L/PR:N/UI:N).
Next-Gen SIEM (SaaS) customers are not affected; CrowdStrike already deployed network-layer mitigations for its SaaS clusters on April 7, 2026. Self-hosted customers must upgrade immediately to a patched release: **1.228.2, 1.233.1, 1.234.1, or 1.235.1**.
References:

