CVE-2026-33458

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-08 18:26

Updated : 2026-07-24 23:10


NVD link : CVE-2026-33458

Mitre link : CVE-2026-33458

CVE.ORG link : CVE-2026-33458


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-918

Server-Side Request Forgery (SSRF)