Junglewise Threat Intelligence

CVE-2026-33462: Elastic Kibana path traversal in dashboard management

CVE-2026-33462 · Severity: medium · CVSS 4.6 · Published 2026-05-28

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and management platform for the Elastic Stack. A security flaw in its dashboard management tool allows a low-privileged user to create a malicious dashboard that, when deleted by an administrator, triggers the unintended deletion of other system resources like user accounts. This could lead to operational disruption and loss of administrative access.

Technical details

A path traversal vulnerability (CWE-22) exists in the dashboard management functionality of Kibana. An authenticated attacker with dashboard creation permissions can craft a dashboard with a malicious identifier containing path traversal sequences. When an administrator attempts to delete this dashboard via the UI, the backend request is redirected to an unintended internal endpoint. This can result in the unauthorized deletion of sensitive resources, including user accounts. The attack requires network access, low-level authentication, and social engineering/interaction from an administrator. The issue is fixed in versions 8.19.16 and 9.3.5.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.15, 9.0.0 to 9.3.4

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory
  • 2026-05-28: patched

References

Related threats