Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic kibana |
|
| Vendors & Products |
Elastic
Elastic kibana |
|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed. | |
| Title | Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-08-13T20:31:50.086Z
Reserved: 2026-08-10T11:17:49.704Z
Link: CVE-2026-72677
Updated: 2026-08-13T20:31:46.099Z
Status : Received
Published: 2026-08-13T20:17:28.373
Modified: 2026-08-13T21:18:12.443
Link: CVE-2026-72677
No data.
OpenCVE Enrichment
Updated: 2026-08-13T21:15:02Z