ZeroHour

CVE-2026-78590

large

Path Traversal in Kibana Fleet Enables Deletion of Privileged Resources

CVSS 3.1
7.3 high
EPSS
<1%p20
Published
()
Modified
AI analysis

Kibana's Fleet feature contains a path traversal flaw (CWE-22, CAPEC-126) that lets an attacker direct administrative actions at unintended internal resources. It is triggered when a low-privileged user holding Fleet Settings write access supplies a malicious pathname, and an administrator subsequently interacts with the affected Fleet interface, causing that administrative action to execute against the wrong targets. The attacker gains deletion of privileged resources such as user accounts and other organizational assets, with high integrity and availability impact but no confidentiality impact per the CVSS 3.1 vector (7.3, AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H). Any Elastic Kibana deployment with the Fleet feature enabled, where non-administrative users have Fleet Settings write permissions, is potentially affected; exploitation additionally requires an administrator to interact with the Fleet UI. There is currently no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates a 0.3% probability of exploitation within 30 days.

What to do: Upgrade Kibana to a patched release per Elastic's advisory for CVE-2026-78590, since exact fixed version numbers are not included in the available data. Until patched, restrict Fleet Settings write permissions to trusted administrators and review Fleet audit logs for unexpected deletions of users or other privileged resources. Administrators should verify Fleet prompts and resource paths before acting on them.

Affected
elastic kibana
Estimated exposure
largetens of thousands of Kibana instances plausibly affected (public internet scans typically show on the order of 10k-100k internet-exposed Kibana hosts, with… — Elastic Stack is among the most widely deployed log and analytics platforms and public scans consistently show tens of thousands of internet-exposed Kibana instances; the affected population is narrower because Fleet must be enabled, users…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged resources such as user accounts and other organizational assets. Exploitation requires an administrator to interact with the affected Fleet interface.

Vendors
elastic
Products
kibana
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.