CVE-2026-33458 PUBLISHED

Server-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information Disclosure

Assigner: elastic
Reserved: 20.03.2026 Published: 08.04.2026 Updated: 08.04.2026

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 6.8

Product Status

Vendor Elastic
Product Kibana
Versions Default: unaffected
  • affected from 9.3.0 to 9.3.2 (incl.)

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE

Impacts

  • CAPEC-664 Server Side Request Forgery