Path Traversal Vulnerability in Elastic Maps Server by Elastic
CVE-2026-78602

5.3MEDIUM

Key Information:

Vendor

Elastic

Vendor
CVE Published:
2 September 2026

What is CVE-2026-78602?

An improper limitation in Elastic Maps Server allows unauthenticated attackers to perform Path Traversal attacks. This vulnerability enables access to files stored outside the intended content directory, leading to potential information disclosure. Attackers with network access to the service may exploit this flaw to read sensitive files that are otherwise inaccessible, posing a significant risk to data security.

Affected Version(s)

Elastic Maps Server 8.19.11 <= 8.19.18

Elastic Maps Server 9.3.0 <= 9.4.3

Elastic Maps Server 9.5.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.