Path traversal in Kibana - CVE-2026-78592

 

Path traversal in Kibana - CVE-2026-78592

Published: September 1, 2026


Vulnerability identifier: #VU146651
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78592
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete privileged resources.

The vulnerability exists due to path traversal in the tag management interface when an administrator interacts with attacker-controlled tag data. A remote user can create a crafted tag to cause a subsequent administrative action to delete privileged resources.

Exploitation requires the attacker to have tag creation privileges, and an administrator must interact with the affected interface.


Affected software

Kibana

How to mitigate CVE-2026-78592

Install security update from vendor's website.

Kibana - addressed in versions 8.19.16, 9.3.5, 9.4.2

External References

Related Security Bulletins