Path traversal in Kibana - CVE-2026-33462

 

Path traversal in Kibana - CVE-2026-33462

Published: May 29, 2026


Vulnerability identifier: #VU132762
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33462
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify or delete unintended internal resources.

The vulnerability exists due to path traversal in Kibana's dashboard management functionality when processing a dashboard deletion request for a specially crafted dashboard identifier. A remote user can create a dashboard with a specially crafted identifier to modify or delete unintended internal resources.

User interaction is required because an administrator must delete the maliciously crafted dashboard through the Kibana interface.


Affected software

Kibana

How to mitigate CVE-2026-33462

Install security update from vendor's website.

Kibana - addressed in versions 8.19.16, 9.3.5

External References

Related Security Bulletins