Path traversal in Kibana - CVE-2026-78591

 

Path traversal in Kibana - CVE-2026-78591

Published: September 2, 2026


Vulnerability identifier: #VU146668
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78591
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete resources.

The vulnerability exists due to path traversal in the Kibana Fleet feature when handling actions in the Fleet administration interface. A remote user can cause a subsequent action by a higher-privileged user to act on an unintended target to delete resources.

Kibana deployments with Fleet enabled where users of differing privilege levels both have access to Fleet configuration are affected. User interaction is required in the Fleet administration interface.


Affected software

Kibana

How to mitigate CVE-2026-78591

Install security update from vendor's website.

Kibana - addressed in versions 8.19.17, 9.3.6, 9.4.3

External References

Related Security Bulletins