Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management interface to act on an unintended target, resulting in the deletion of privileged resources including administrative accounts and other organizational assets. Exploitation requires an administrator to interact with the affected interface.
Published: 2026-09-01
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Deletion of Privileged Resources
Action: Patch
AI Analysis

Impact

The vulnerability in Elastic Kibana allows a path traversal flaw (CWE‑22) to be exploited by a low‑privileged user with tag‑creation rights. By manipulating the file path used during tag creation, the user can trick a later administrative action into operating on an unintended target. This can result in the deletion of privileged resources, such as administrative accounts and other critical organizational assets. The flaw effectively removes the boundary that should restrict file access to a designated directory, enabling destructive changes.

Affected Systems

Elastic Kibana is the affected product. No specific version numbers are listed in the advisory; the issue is tied to the Kibana instance that supports tag management and the path‑validation logic.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, but the exploitation requires an administrator to open the affected tag‑management interface after the low‑privilege action. The attack thus depends on an interaction step that an admin may or may not perform, reducing the likelihood of uncoordinated exploitation. EPSS data is unavailable and the vulnerability is not currently listed in CISA’s KEV catalog. Nonetheless, the potential to permanently delete privileged resources warrants immediate attention, especially in environments where administrative privileges are broadly distributed.

Generated by OpenCVE AI on September 2, 2026 at 02:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Elastic security update for Kibana (ES_UPDATE-2026-160), as referenced in the discussion post.
  • Restrict tag‑creation privileges to a minimal set of trusted users and consider disabling this feature if it is not required.
  • Implement monitoring and logging of administrative actions in Kibana, and set alerts for unexpected deletions of privileged resources.

Generated by OpenCVE AI on September 2, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Wed, 02 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management interface to act on an unintended target, resulting in the deletion of privileged resources including administrative accounts and other organizational assets. Exploitation requires an administrator to interact with the affected interface.
Title Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:39:13.848Z

Reserved: 2026-08-24T21:13:51.298Z

Link: CVE-2026-78592

cve-icon Vulnrichment

Updated: 2026-09-01T19:39:10.784Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:23.387

Modified: 2026-09-02T14:52:18.073

Link: CVE-2026-78592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:15:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')