Junglewise Threat Intelligence

CVE-2026-0532: Elastic Kibana SSRF and arbitrary file disclosure in Google Gemini connector

CVE-2026-0532 · Severity: high · CVSS 8.6 · Published 2026-01-14

Technologies: Elastic Kibana. Vendors: Elastic, Red Hat.

Executive brief

Kibana is a data visualization and management dashboard for the Elastic Stack. A vulnerability in its Google Gemini connector allows an authorized user to trick the server into reading sensitive files or making unauthorized network requests. This could lead to the exposure of internal system data or a breach of confidentiality for information stored on the server.

Technical details

A vulnerability combining External Control of File Name or Path (CWE-73) and Server-Side Request Forgery (SSRF) (CWE-918) exists in the Kibana Google Gemini connector. An attacker with 'Alerts & Connectors: All' privileges can provide a specially crafted credentials JSON payload during connector configuration. Because the server processes this configuration without proper validation, it can be coerced into performing arbitrary network requests or reading arbitrary files from the local file system. The issue is resolved in Kibana versions 8.19.10, 9.1.10, and 9.2.4. As a mitigation, users can disable the affected connector type via the xpack.actions.enabledActionTypes setting.

Affected products

  • Elastic Kibana 8.15.0 to 8.19.9, 9.0.0 to 9.1.9, 9.2.0 to 9.2.3
  • Red Hat Red Hat OpenShift distributed tracing 3 3

Timeline

  • 2026-01-13: advisory: Elastic published security update ESA-2026-05
  • 2026-01-14: disclosed: CVE-2026-0532 published to NVD

References

Related threats