Path traversal in Kibana - CVE-2026-78590
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to delete privileged resources.
The vulnerability exists due to path traversal in the Kibana Fleet feature when processing Fleet settings that are later used by the affected interface. A remote user can modify Fleet settings to cause a subsequent administrative action to delete privileged resources.
Exploitation requires an administrator to interact with the affected Fleet interface, and only deployments where users have Fleet Settings write privileges are affected.