Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78590— Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources

Quick assessment

Affected
Elastic Kibana
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kibana Fleet 功能中存在路径遍历(CWE-22)漏洞:限制路径名到受限目录的机制不当。 Kibana 的 Fleet 功能中,对路径名的限制机制存在缺陷,可能引发路径遍历问题(CWE-22)。这种缺陷可导致低权限用户通过路径遍历(CAPEC-126)非授权地删除受保护的资源。 具体而言,拥有 Fleet 设置写入权限的低权限用户能够构造特定路径,使得后续由管理员执行的管理操作错误地作用于非预期的内部资源,进而导致用户账户及其他组织资产等受保护资源被意外删除。 利用该漏洞需要管理员与受影响的 Fleet

CVSS 7.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78590

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged resources such as user accounts and other organizational assets. Exploitation requires an administrator to interact with the affected Fleet interface.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Elastic Kibana 8.0.0 ~ 8.19.17 -

II. Public POCs for CVE-2026-78590

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78590

登录查看更多情报信息。

Other References for CVE-2026-78590 (1)

Same Patch Batch · Elastic · 2026-09-02 · 15 CVEs total

CVE-2026-78604 7.8 HIGH Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Pr
CVE-2026-78588 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Serv
CVE-2026-78586 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-78599 6.5 MEDIUM Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources
CVE-2026-78591 6.3 MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L
CVE-2026-78601 5.5 MEDIUM Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure
CVE-2026-78598 5.4 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine
CVE-2026-78609 5.4 MEDIUM Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modificatio
CVE-2026-78602 5.3 MEDIUM Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading
CVE-2026-78594 4.9 MEDIUM Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of
CVE-2026-82293 4.3 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption
CVE-2026-78584 4.3 MEDIUM Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
CVE-2026-78600 3.5 LOW Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace
CVE-2026-78587 3.1 LOW Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Opera

IV. Related Vulnerabilities

V. Comments for CVE-2026-78590

No comments yet


Leave a comment