ZeroHour

CVE-2026-78592

large

Path Traversal in Elastic Kibana Enables Deletion of Privileged Resources

CVSS 3.1
7.3 high
EPSS
<1%p16
Published
()
Modified
AI analysis

Elastic Kibana contains a path traversal flaw (CWE-22, CAPEC-126) in its tag management functionality that can cause an administrative action to act on an unintended target outside the restricted directory scope. A low-privileged user who holds tag creation privileges can set up a path traversal such that, when an administrator subsequently interacts with the tag management interface, the resulting action deletes privileged resources rather than the intended object, including administrative accounts and other organizational assets. An attacker gains high-value resource destruction with no confidentiality impact (CVSS 7.3 high: AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H), but exploitation requires both a low-privilege account with tag creation rights and an administrator touching the affected interface. Any organization running an affected version of Kibana in which low-privileged users can create tags and administrators manage them is potentially exposed; the advisory was assigned by Elastic ([email protected]). As of the provided data there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days (16th percentile), so no exploitation is known in the wild.

What to do: Inventory all Kibana instances and apply the patched release identified in Elastic's security advisory (affected/patched version numbers were not included in the provided data). Until patched, restrict tag creation privileges to trusted users and have administrators verify the target before performing tag-management actions, since exploitation only completes when an administrator interacts with that interface. Monitor Kibana audit logs for unexpected deletions of administrative accounts or other privileged resources.

Affected
Elastic Kibana
Estimated exposure
largelikely hundreds of thousands of Kibana deployments, including tens of thousands of internet-exposed instances (estimate) — Kibana ships by default with the Elastic Stack, one of the most widely deployed search/observability platforms, and public internet scans routinely index on the order of tens of thousands of internet-facing Kibana hosts; no vendor install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management interface to act on an unintended target, resulting in the deletion of privileged resources including administrative accounts and other organizational assets. Exploitation requires an administrator to interact with the affected interface.

Vendors
elastic
Products
kibana
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.