Path traversal in Kibana - CVE-2026-78590

 

Path traversal in Kibana - CVE-2026-78590

Published: September 2, 2026


Vulnerability identifier: #VU146667
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78590
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete privileged resources.

The vulnerability exists due to path traversal in the Kibana Fleet feature when processing Fleet settings that are later used by the affected interface. A remote user can modify Fleet settings to cause a subsequent administrative action to delete privileged resources.

Exploitation requires an administrator to interact with the affected Fleet interface, and only deployments where users have Fleet Settings write privileges are affected.


Affected software

Kibana

How to mitigate CVE-2026-78590

Install security update from vendor's website.

Kibana - addressed in versions 8.19.18, 9.3.6, 9.4.3

External References

Related Security Bulletins