Path traversal in Kibana - CVE-2026-78599
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to path traversal in the Kibana Fleet feature when processing delete actions on stored paths. A remote user can cause a subsequent administrative delete action to act on unintended internal resources to cause a denial of service.
Exploitation requires an administrator to interact with the affected Fleet interface.