CVE-2026-78591 PUBLISHED

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource Deletion

Assigner: elastic
Reserved: 24.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L
CVSS Score: 6.3

Product Status

Vendor Elastic
Product Kibana
Versions Default: unaffected
  • affected from 8.0.0 to 8.19.16 (incl.)
  • affected from 9.0.0 to 9.3.5 (incl.)
  • affected from 9.4.0 to 9.4.2 (incl.)

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-126 Path Traversal