Junglewise Threat Intelligence

CVE-2026-33458: Elastic Kibana SSRF in One Workflow

CVE-2026-33458 · Severity: medium · CVSS 6.3 · Published 2026-04-08

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

A security vulnerability exists in Kibana, a popular data visualization and management platform. An authorized user with the ability to create and run workflows could bypass security restrictions to access sensitive internal systems or data that should normally be protected. This could lead to the exposure of private internal information or unauthorized access to other services within the corporate network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the Kibana One Workflow Execution Engine. The flaw allows an authenticated attacker with workflow creation and execution privileges to bypass configured host allowlist restrictions. This is achieved by exploiting the engine's handling of HTTP redirects during workflow steps, enabling the attacker to force the Kibana server to make requests to unauthorized internal endpoints. The vulnerability affects Kibana versions 9.3.0 through 9.3.2 and is resolved in version 9.3.3. Exploitation requires network access and valid user credentials with specific workflow permissions.

Affected products

  • Elastic Kibana 9.3.0 to 9.3.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched: Fixed in version 9.3.3

References

Related threats