#VU125551 Server-Side Request Forgery (SSRF) in Kibana - CVE-2026-33458
Published: April 9, 2026
Kibana
Elastic Stack
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to server-side request forgery in Kibana One Workflow Workflows Execution Engine when processing workflow HTTP steps that follow redirects. A remote user can send a specially crafted workflow to disclose sensitive information.
Exploitation requires workflow creation and execution privileges, and only deployments with the Workflows Execution Engine enabled are vulnerable.