SB2026090225 - Multiple vulnerabilities in Kibana



SB2026090225 - Multiple vulnerabilities in Kibana

Published: September 2, 2026

Security Bulletin ID SB2026090225
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Path traversal (CVE-ID: CVE-2026-78599)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to path traversal in the Kibana Fleet feature when processing delete actions on stored paths. A remote user can cause a subsequent administrative delete action to act on unintended internal resources to cause a denial of service.

Exploitation requires an administrator to interact with the affected Fleet interface.


2) Path traversal (CVE-ID: CVE-2026-78590)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to delete privileged resources.

The vulnerability exists due to path traversal in the Kibana Fleet feature when processing Fleet settings that are later used by the affected interface. A remote user can modify Fleet settings to cause a subsequent administrative action to delete privileged resources.

Exploitation requires an administrator to interact with the affected Fleet interface, and only deployments where users have Fleet Settings write privileges are affected.


3) Path traversal (CVE-ID: CVE-2026-78591)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to delete resources.

The vulnerability exists due to path traversal in the Kibana Fleet feature when handling actions in the Fleet administration interface. A remote user can cause a subsequent action by a higher-privileged user to act on an unintended target to delete resources.

Kibana deployments with Fleet enabled where users of differing privilege levels both have access to Fleet configuration are affected. User interaction is required in the Fleet administration interface.


Remediation

Install update from vendor's website.