Junglewise Threat Intelligence

CVE-2026-78599: Elastic Kibana path traversal in Fleet leading to unauthorized deletion

CVE-2026-78599 · Severity: medium · CVSS 6.5 · Published 2026-09-02

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a visualization and analytics tool used to monitor and analyze data in the Elastic Stack. A path traversal vulnerability in the Fleet feature allows a low-privileged user to craft malicious requests that, when interacted with by an administrator, can cause deletion of unintended internal resources. This could result in unauthorized data loss or system disruption.

Technical details

A path traversal vulnerability (CWE-22) exists in Kibana's Fleet feature where improper validation of pathname inputs allows directory traversal attacks (CAPEC-126). A user with Fleet write access can inject specially crafted paths that, when processed by administrative delete operations, cause the deletion of internal resources outside the intended scope. The vulnerability is network-reachable and requires a low privilege account with Fleet write permissions and subsequent interaction by an administrator through the Fleet interface. Fixes are available in Kibana 8.19.18 and 9.4.3.

Affected products

  • Elastic Kibana 8.0.0–8.19.17, 9.0.0–9.4.2

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in Kibana 8.19.18 and 9.4.3

References

Related threats