Path Traversal Vulnerability in Elastic Maps Server by Elastic
CVE-2026-78602
5.3MEDIUM
What is CVE-2026-78602?
An improper limitation in Elastic Maps Server allows unauthenticated attackers to perform Path Traversal attacks. This vulnerability enables access to files stored outside the intended content directory, leading to potential information disclosure. Attackers with network access to the service may exploit this flaw to read sensitive files that are otherwise inaccessible, posing a significant risk to data security.
Affected Version(s)
Elastic Maps Server 8.19.11 <= 8.19.18
Elastic Maps Server 9.3.0 <= 9.4.3
Elastic Maps Server 9.5.0