CVE-2026-0532
EUVD-2026-251714.01.2026, 11:15
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | kibana | 8.15.0 ≤ 𝑥 ≤ 8.19.9 | CNA |
| elastic | kibana | 9.0.0 ≤ 𝑥 ≤ 9.1.9 | CNA |
| elastic | kibana | 9.2.0 ≤ 𝑥 ≤ 9.2.3 | CNA |