CrowdStrike LogScale Unauthenticated Path Traversal Vulnerability

Vulnerability

A critical unauthenticated path traversal vulnerability has been identified in CrowdStrike LogScale self-hosted versions 1.224.0 through 1.234.0, including LogScale Self-Hosted LTS versions 1.228.0 and 1.228.1. This vulnerability exists in a specific cluster API endpoint, allowing remote attackers to read arbitrary files from the server filesystem without authentication. CrowdStrike has no evidence of exploitation of this vulnerability in the wild.

Impact

Exploitation of this vulnerability allows for unauthorized access to read files from the server's filesystem, potentially leading to the disclosure of sensitive information.

Remediation

CrowdStrike has released patched versions to address this vulnerability. Self-hosted customers should upgrade to version 1.235.1 or later, 1.234.1 or later, 1.233.1 or later, or 1.228.2 (LTS) or later.

Added: Apr 21, 2026, 6:51 PM
Updated: Apr 21, 2026, 6:51 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
7.0
remediation
0.0
relevance
6.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.