Security Assessment of Erlang/OTP and Redis CVEs for Carbon Black EDR 7.9.1
search cancel

Security Assessment of Erlang/OTP and Redis CVEs for Carbon Black EDR 7.9.1

book

Article ID: 452078

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

Customers may inquire whether Carbon Black Endpoint Detection and Response(EDR) 7.9.1 is vulnerable to various CVEs related to Erlang/OTP (20 CVEs) and Redis (3 CVEs).


Vulnerability:


CVE-2026-55952
CVE-2026-55950
CVE-2026-54891
CVE-2026-54887
CVE-2026-54886
CVE-2026-53422
CVE-2026-49760
CVE-2026-49759
CVE-2026-48860
CVE-2026-48858
CVE-2026-48856
CVE-2026-48855
CVE-2026-42790
CVE-2026-42789
CVE-2026-32147
CVE-2026-28810
CVE-2026-28808
CVE-2026-23943
CVE-2026-23942
CVE-2026-23941
CVE-2026-25243
CVE-2026-23631
CVE-2026-23479

Environment

7.9.1, 7.9.2

Resolution

Carbon Black EDR is not exploitable by these CVEs in the default configuration.

 

Erlang/OTP (20 CVEs): Not exploitable in the default CB EDR configuration — the affected sub-modules aren't used, and Erlang clustering traffic is restricted by firewall to cluster nodes only. Upgrading to 7.9.3 (Erlang 27.3.4.14) will fully remediate these at the package level.

Redis (3 CVEs): With the default firewall setup managed by EDR, Redis is not reachable outside trusted/cluster-node traffic, so these are not exploitable in a default deployment. For defense-in-depth, we still recommend applying the authentication and encryption steps in the "Securing Redis" section of the CB EDR 7.9.1 admin guide:

Securing Redis

Enable Redis Network Encryption