Junglewise Threat Intelligence

CVE-2026-78591: Elastic Kibana path traversal in Fleet feature

CVE-2026-78591 · Severity: medium · CVSS 6.3 · Published 2026-09-02

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, Elastic's data visualization and administration tool, contains a path traversal vulnerability in its Fleet feature that allows low-privileged users to manipulate file paths. An attacker could trick a higher-privileged administrator into deleting unintended resources, including accounts with elevated permissions, by crafting malicious path inputs that bypass directory restrictions. This could lead to unauthorized account deletion and disruption of critical administrative functions.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in Kibana's Fleet administration feature that fails to properly restrict pathname inputs. An attacker with low privileges can craft a malicious path that exploits this validation weakness, causing a subsequent action by a higher-privileged user (requiring user interaction via the Fleet admin interface) to operate on an unintended target directory or resource. The vulnerability enables unauthorized deletion of arbitrary resources, including high-privilege user accounts. Attack vector is network-based with low privilege requirement and requires user interaction (UI:R). Patches are available in Kibana 8.19.17, 9.3.6, and 9.4.3; no workarounds exist for affected deployments with Fleet enabled.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.16, 9.0.0 to 9.3.5, 9.4.0 to 9.4.2

Timeline

  • 2026-09-02: disclosed: CVE-2026-78591 disclosed publicly
  • 2026-09-02: patched: Fixed in Kibana 8.19.17, 9.3.6, and 9.4.3

References

Related threats