Path Traversal Vulnerability in Logstash Affects Elastic.co Products
CVE-2026-33466
8.1HIGH
What is CVE-2026-33466?
A vulnerability in Logstash arises from improper validation of file paths within compressed archives. This weakness allows attackers to exploit the system by serving manipulated archive files through a compromised update endpoint. As a result, arbitrary files can be written to the filesystem with Logstash's privileges. In specific configurations with automatic pipeline reloading enabled, this vulnerability poses a significant risk of escalating to remote code execution, making it critical for users to apply security updates promptly.
Affected Version(s)
Logstash 8.0.0 <= 8.19.13