Junglewise Threat Intelligence

CVE-2026-49091: Elastic Kibana log injection in log output

CVE-2026-49091 · Severity: high · CVSS 8 · Published 2026-07-01

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a popular data visualization and management platform for the Elastic Stack, is vulnerable to a log injection flaw. An attacker can provide malicious input that, when recorded in system logs, can manipulate how those logs appear to administrators viewing them in a command-line terminal. This could allow an attacker to hide their activities or forge log entries, potentially misleading security investigations or operational monitoring.

Technical details

A log injection vulnerability exists in Kibana due to improper neutralization of output for logs (CWE-117). An authenticated attacker with network access can supply specially crafted input containing terminal control sequences. When these sequences are written to log files and subsequently viewed in a terminal that interprets such sequences, the attacker can alter the displayed log data (CAPEC-93). This can be used to forge log entries or hide malicious activity. The vulnerability is mitigated if logs are viewed in tools that do not interpret terminal control sequences. Patches are available in versions 7.17.15 and 8.11.1.

Affected products

  • Elastic Kibana 7.0.0 to 7.17.14, 8.0.0 to 8.11.0

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory
  • 2026-07-01: patched

References

Related threats