Executive brief
Kibana, a data visualization and management platform used to search, view, and interact with data stored in Elasticsearch clusters, contains a path traversal vulnerability in its Fleet feature. An attacker with low-level write permissions to Fleet Settings could trick an administrator into deleting sensitive resources such as user accounts or critical organizational assets when the administrator interacts with the Fleet interface.
Technical details
A path traversal vulnerability (CWE-22) exists in the Kibana Fleet feature that allows a low-privileged user with Fleet Settings write access to craft malicious input that causes the application to access unintended internal resources outside a restricted directory. The vulnerability requires social engineering or administrative interaction—specifically, an administrator must interact with the affected Fleet interface—to trigger the actual deletion of privileged resources. An attacker can exploit this to delete critical resources including user accounts and organizational assets. The vulnerability is patched in Kibana versions 8.19.18, 9.3.6, and 9.4.3.
Affected products
- Elastic Kibana 8.0.0 to 8.19.17; 9.0.0 to 9.3.5; 9.4.0 to 9.4.2
Timeline
- 2026-09-02: disclosed: CVE-2026-78590 disclosed via NVD and Elastic Security Advisory ESA-2026-158
- 2026-09-02: patched: Fixed in Kibana 8.19.18, 9.3.6, and 9.4.3