Path traversal in Kibana - CVE-2026-78592
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to delete privileged resources.
The vulnerability exists due to path traversal in the tag management interface when an administrator interacts with attacker-controlled tag data. A remote user can create a crafted tag to cause a subsequent administrative action to delete privileged resources.
Exploitation requires the attacker to have tag creation privileges, and an administrator must interact with the affected interface.