#VU121290 Server-Side Request Forgery (SSRF) in Kibana - CVE-2026-0532
Published: January 13, 2026
Kibana
Elastic Stack
Description
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted a specially crafted credentials JSON payload in the Google Gemini connector configuration and read contents of arbitrary files on the system or initiate requests to internal system.