Path Traversal Vulnerability in Kibana Dashboard Management by Elastic
CVE-2026-33462
4.6MEDIUM
What is CVE-2026-33462?
A path traversal vulnerability in Kibana's dashboard management feature could allow an authenticated user with limited permissions to manipulate dashboard identifiers. If an administrator attempts to delete such a crafted dashboard, the request may inadvertently redirect to an internal endpoint, which could lead to unauthorized deletion of user accounts or other critical resources. Exploitability hinges on the administrator executing a delete operation on the compromised dashboard.
Affected Version(s)
Kibana 9.0.0 <= 9.3.4
Kibana 8.0.0 <= 8.19.15