Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78599— Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources

Quick assessment

Affected
Elastic Kibana
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kibana 的 Fleet 功能中存在对受限制目录中的路径名限制不当的问题(即“路径遍历”,CWE-22),可能导致通过路径遍历(CAPEC-126)非授权地删除内部资源。拥有 Fleet 写权限的低权限用户可以触发后续的管理员删除操作,使其作用于非预期的内部资源。利用该漏洞需要管理员与受影响的 Fleet 界面进行交互。

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78599

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Elastic Kibana 8.0.0 ~ 8.19.17 -

II. Public POCs for CVE-2026-78599

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78599

登录查看更多情报信息。

Other References for CVE-2026-78599 (1)

Same Patch Batch · Elastic · 2026-09-02 · 15 CVEs total

CVE-2026-78604 7.8 HIGH Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Pr
CVE-2026-78590 7.3 HIGH Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori
CVE-2026-78588 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Serv
CVE-2026-78586 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-78591 6.3 MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L
CVE-2026-78601 5.5 MEDIUM Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure
CVE-2026-78598 5.4 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine
CVE-2026-78609 5.4 MEDIUM Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modificatio
CVE-2026-78602 5.3 MEDIUM Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading
CVE-2026-78594 4.9 MEDIUM Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of
CVE-2026-82293 4.3 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption
CVE-2026-78584 4.3 MEDIUM Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
CVE-2026-78600 3.5 LOW Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace
CVE-2026-78587 3.1 LOW Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Opera

IV. Related Vulnerabilities

V. Comments for CVE-2026-78599

No comments yet


Leave a comment