Path traversal in Kibana - CVE-2026-78591
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to delete resources.
The vulnerability exists due to path traversal in the Kibana Fleet feature when handling actions in the Fleet administration interface. A remote user can cause a subsequent action by a higher-privileged user to act on an unintended target to delete resources.
Kibana deployments with Fleet enabled where users of differing privilege levels both have access to Fleet configuration are affected. User interaction is required in the Fleet administration interface.