Server-Side Request Forgery (SSRF) in Kibana - CVE-2026-42398
Published: May 29, 2026
Kibana
Detailed vulnerability description
The vulnerability allows a remote user to access unauthorized network destinations.
The vulnerability exists due to server-side request forgery in Webhook connector handling when configuring a crafted target. A remote user can configure a Webhook connector with a crafted target to access unauthorized network destinations.
Only deployments where the xpack.actions.allowedHosts setting is configured to restrict outbound connector connections are affected.