Relative Path Traversal Vulnerability in Kibana by Elastic
CVE-2026-72677
7.3HIGH
What is CVE-2026-72677?
A vulnerability exists in Kibana that allows for unauthorized resource deletion via a Relative Path Traversal attack. This occurs when Kibana Fleet accepts an unvalidated user-supplied identifier for a Fleet Server host configuration, failing to reject relative traversal sequences. As a result, the identifier is stored without sanitization and is subsequently used in requests to remove configurations, potentially leading to the unauthorized deletion of critical resources.
Affected Version(s)
Kibana 8.0.0 <= 8.19.16
Kibana 9.0.0 <= 9.3.5
Kibana 9.4.0 <= 9.4.2