CVE-2026-78593

An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized Elasticsearch permissions.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 19:17

Updated : 2026-09-08 14:17


NVD link : CVE-2026-78593

Mitre link : CVE-2026-78593

CVE.ORG link : CVE-2026-78593


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')