Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-94/389512 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-13 20:17
Updated : 2026-09-02 14:09
NVD link : CVE-2026-72677
Mitre link : CVE-2026-72677
CVE.ORG link : CVE-2026-72677
JSON object : View
Products Affected
elastic
- kibana
CWE
CWE-23
Relative Path Traversal
