Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
Published: 2026-09-02
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw in the Kibana Fleet feature allows a low‑privileged user to supply an arbitrary pathname that bypasses directory restrictions, causing the application to delete resources it should not touch. The effect can include the removal of accounts that possess elevated privileges, leading to loss of critical data and potential service disruption.

Affected Systems

Elastic Kibana is affected. No specific product versions are listed in the advisory; updates mentioned in the discussion thread should be applied as soon as they become available.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.3, indicating a moderate risk. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. A non‑admin user can trigger the flaw by interacting with the Fleet interface, and the resulting deletion occurs in the context of a higher‑privileged action. The attack requires authenticated access to Kibana and the ability to send a crafted request to the Fleet endpoint, but no extensive pre‑conditions are described.

Generated by OpenCVE AI on September 3, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana update referenced in Elastic’s security advisory
  • Restrict access to the Fleet administration interface to authorized users only, enforcing role‑based access controls
  • Audit and monitor deletion logs for anomalous activity and investigate any accidental or malicious deletions

Generated by OpenCVE AI on September 3, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Thu, 03 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
Title Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource Deletion
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T15:58:11.652Z

Reserved: 2026-08-24T21:13:51.298Z

Link: CVE-2026-78591

cve-icon Vulnrichment

Updated: 2026-09-02T15:50:25.337Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T15:17:40.570

Modified: 2026-09-03T13:43:14.230

Link: CVE-2026-78591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')