Path Traversal Vulnerability in Kibana Fleet by Elastic
CVE-2026-78590

7.3HIGH

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-78590?

The Kibana Fleet feature has a security flaw that allows a low-privileged user with write access to Fleet Settings to exploit path traversal vulnerabilities. This could enable them to trigger administrative actions that unintentionally manipulate internal resources, including the potential deletion of critical assets like user accounts. Exploitation is contingent upon an administrator's interaction with the vulnerable Fleet interface, highlighting the need for heightened security measures in managing user permissions and validating input to mitigate this risk.

Affected Version(s)

Kibana 8.0.0 <= 8.19.17

Kibana 9.0.0 <= 9.3.5

Kibana 9.4.0 <= 9.4.2

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.