Executive brief
Kibana, Elastic's visualization and analytics platform, contains a path traversal vulnerability in its tag management interface that allows unauthorized deletion of privileged resources. A low-privileged user with tag creation permissions can manipulate the tag system to trick an administrator into deleting critical assets, including admin accounts. Exploitation requires admin interaction and could result in loss of account control and organizational asset deletion.
Technical details
A path traversal vulnerability (CWE-22) exists in Kibana's tag management interface where improper pathname validation allows low-privileged users to craft malicious tag paths. When a low-privileged user with tag creation privileges exploits this flaw, a subsequent administrative action in the tag management interface can be redirected to act on unintended targets outside the restricted directory scope. An authenticated attacker can cause deletion of privileged resources including administrative accounts and other organizational assets, but exploitation requires social engineering or direct admin interaction with the affected interface. The vulnerability is fixed in Kibana 8.19.16, 9.3.5, and 9.4.2; versions 7.11.0–7.17.29, 8.0.0–8.19.15, and 9.0.0–9.4.1 are affected.
Affected products
- Elastic Kibana 7.11.0–7.17.29, 8.0.0–8.19.15, 9.0.0–9.4.1
Timeline
- 2026-09-01: disclosed: CVE-2026-78592 published
- 2026-09-01: patched: Fixed in Kibana 8.19.16, 9.3.5, and 9.4.2