CVE-2026-78590 PUBLISHED

Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources

Assigner: elastic
Reserved: 24.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged resources such as user accounts and other organizational assets. Exploitation requires an administrator to interact with the affected Fleet interface.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
CVSS Score: 7.3

Product Status

Vendor Elastic
Product Kibana
Versions Default: unaffected
  • affected from 8.0.0 to 8.19.17 (incl.)
  • affected from 9.0.0 to 9.3.5 (incl.)
  • affected from 9.4.0 to 9.4.2 (incl.)

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-126 Path Traversal