Code Injection in Kibana - CVE-2026-78593
Published: September 3, 2026
Vulnerability details
The vulnerability allows a remote user to modify an Elasticsearch ingest pipeline beyond the caller's authorized Elasticsearch permissions.
The vulnerability exists due to improper control of generation of code in Kibana's Cribl integration when processing an insufficiently validated configuration field in a server-side script template. A remote user can inject attacker-controlled expressions to modify an Elasticsearch ingest pipeline beyond the caller's authorized Elasticsearch permissions.
Only deployments with the Cribl integration installed are vulnerable.