Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78592— Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources

Quick assessment

Affected
Elastic Kibana
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kibana 中存在一个“路径名未限制在受限目录内”(路径遍历)漏洞(CWE-22),可能通过路径遍历导致特权资源被未授权删除(CAPEC-126)。拥有标签创建权限的低权限用户可以通过路径遍历,使管理员在标签管理界面执行的后续管理操作作用于非预期目标,从而导致包括管理员账户在内的特权资源被删除。利用该漏洞需要一位管理员与受影响的用户界面进行交互。

CVSS 7.3 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 4

VendorProduct Version RangeStatus
Elastic Kibana 7.11.0≤ 7.17.29 affected
8.0.0≤ 8.19.15 affected
9.0.0≤ 9.3.4 affected
9.4.0≤ 9.4.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78592

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management interface to act on an unintended target, resulting in the deletion of privileged resources including administrative accounts and other organizational assets. Exploitation requires an administrator to interact with the affected interface.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Elastic Kibana 7.11.0 ~ 7.17.29 -

II. Public POCs for CVE-2026-78592

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78592

登录查看更多情报信息。

Other References for CVE-2026-78592 (1)

Same Patch Batch · Elastic · 2026-09-01 · 20 CVEs total

CVE-2026-72649 8.8 HIGH Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
CVE-2026-63137 8.3 HIGH Incorrect Authorization in Kibana Leading to Privilege Escalation
CVE-2024-14047 7.2 HIGH Improper Link Resolution Before File Access ('Link Following') in Winlogbeat Leading to Ar
CVE-2026-78608 6.5 MEDIUM Missing Authorization in Kibana Leading to Information Disclosure
CVE-2026-33465 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-63138 6.5 MEDIUM Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Infor
CVE-2026-72654 6.5 MEDIUM Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure
CVE-2026-72628 6.5 MEDIUM Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service
CVE-2026-72652 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-72644 6.5 MEDIUM Uncaught Exception in Kibana Leading to Denial of Service
CVE-2026-72682 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-78605 5.9 MEDIUM Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch L
CVE-2026-78607 5.4 MEDIUM Missing Authorization in Elasticsearch Leading to Information Disclosure
CVE-2026-72641 5.4 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data
CVE-2026-56143 4.9 MEDIUM Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of
CVE-2026-72633 4.3 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin
CVE-2026-78603 4.3 MEDIUM Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met
CVE-2026-78597 4.3 MEDIUM Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation
CVE-2026-78606 4.2 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and De

IV. Related Vulnerabilities

V. Comments for CVE-2026-78592

No comments yet


Leave a comment