CVE-2026-78599
EUVD-2026-7006002.09.2026, 15:17
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | kibana | 8.0.0 ≤ 𝑥 ≤ 8.19.17 | CNA |
| elastic | kibana | 9.0.0 ≤ 𝑥 ≤ 9.4.2 | CNA |
Vulnerability Media Exposure