Code Injection in Kibana - CVE-2026-78593

 

Code Injection in Kibana - CVE-2026-78593

Published: September 3, 2026


Vulnerability identifier: #VU146879
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78593
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify an Elasticsearch ingest pipeline beyond the caller's authorized Elasticsearch permissions.

The vulnerability exists due to improper control of generation of code in Kibana's Cribl integration when processing an insufficiently validated configuration field in a server-side script template. A remote user can inject attacker-controlled expressions to modify an Elasticsearch ingest pipeline beyond the caller's authorized Elasticsearch permissions.

Only deployments with the Cribl integration installed are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-78593

Install security update from vendor's website.

Kibana - addressed in versions 8.19.21, 9.4.6, 9.5.3

External References

Related Security Bulletins