Server-Side Request Forgery (SSRF) in Kibana - CVE-2026-33458

 

Server-Side Request Forgery (SSRF) in Kibana - CVE-2026-33458

Published: April 9, 2026


Vulnerability identifier: #VU125551
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2026-33458
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to server-side request forgery in Kibana One Workflow Workflows Execution Engine when processing workflow HTTP steps that follow redirects. A remote user can send a specially crafted workflow to disclose sensitive information.

Exploitation requires workflow creation and execution privileges, and only deployments with the Workflows Execution Engine enabled are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-33458

Install security update from vendor's website.

Kibana - update to 9.3.3

External References

Related Security Bulletins