Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78602— Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading to Unauthorized File Disclosure

Quick assessment

Affected
Elastic Elastic Maps Server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Elastic Maps Server 中存在路径限制不当(路径遍历)(CWE-22)缺陷,可能导致信息泄露(CAPEC-126)。能够通过网络访问该服务的未认证攻击者可以诱导其返回位于预期内容目录之外的、且可被服务器进程读取的文件的文件内容。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78602

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading to Unauthorized File Disclosure
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Elastic Elastic Maps Server 8.19.11 ~ 8.19.18 -

II. Public POCs for CVE-2026-78602

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78602

登录查看更多情报信息。

Other References for CVE-2026-78602 (1)

Same Patch Batch · Elastic · 2026-09-02 · 15 CVEs total

CVE-2026-78604 7.8 HIGH Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Pr
CVE-2026-78590 7.3 HIGH Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori
CVE-2026-78588 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Serv
CVE-2026-78586 6.5 MEDIUM Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-78599 6.5 MEDIUM Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources
CVE-2026-78591 6.3 MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L
CVE-2026-78601 5.5 MEDIUM Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure
CVE-2026-78598 5.4 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine
CVE-2026-78609 5.4 MEDIUM Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modificatio
CVE-2026-78594 4.9 MEDIUM Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of
CVE-2026-82293 4.3 MEDIUM Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption
CVE-2026-78584 4.3 MEDIUM Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
CVE-2026-78600 3.5 LOW Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace
CVE-2026-78587 3.1 LOW Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Opera

IV. Related Vulnerabilities

V. Comments for CVE-2026-78602

No comments yet


Leave a comment