#VU125551 Server-Side Request Forgery (SSRF) in Kibana - CVE-2026-33458

 

#VU125551 Server-Side Request Forgery (SSRF) in Kibana - CVE-2026-33458

Published: April 9, 2026


Vulnerability identifier: #VU125551
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-33458
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Kibana
Software vendor:
Elastic Stack

Description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to server-side request forgery in Kibana One Workflow Workflows Execution Engine when processing workflow HTTP steps that follow redirects. A remote user can send a specially crafted workflow to disclose sensitive information.

Exploitation requires workflow creation and execution privileges, and only deployments with the Workflows Execution Engine enabled are vulnerable.


Remediation

Install security update from vendor's website.

External links