Cross-site scripting in Kibana - CVE-2026-42401

 

Cross-site scripting in Kibana - CVE-2026-42401

Published: May 29, 2026


Vulnerability identifier: #VU132761
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-42401
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to manipulate the user interface and trigger outbound network requests from the victim's browser session.

The vulnerability exists due to cross-site scripting in an affected Kibana view when rendering crafted markup persisted in an Elasticsearch index. A remote user can store crafted markup in an Elasticsearch index to manipulate the user interface and trigger outbound network requests from the victim's browser session.

User interaction is required when another user views the affected Kibana content.


Affected software

Kibana

How to mitigate CVE-2026-42401

Install security update from vendor's website.

Kibana - addressed in versions 8.19.16, 9.3.5

External References

Related Security Bulletins