Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.
Published: 2026-09-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The identified issue is a path traversal flaw in the Kibana Fleet feature that permits a low‑privileged user with write access to trigger an administrative delete operation on unintended internal resources. This weakness, classified as CWE‑22, effectively allows the attacker to delete data that should be protected by the application's directory restrictions. The vulnerability exploits the lack of proper pathname limitation and leverages the Fleet interface to conduct the deletion.

Affected Systems

The affected product is Elastic’s Kibana suite. No specific version numbers are provided in the advisory, so any Kibana installation that incorporates the Fleet feature and has not received the latest security update is potentially impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability, and the EPSS score is not available, suggesting limited publicly known exploitation data. Because the exploit requires the administrator to interact with the Fleet interface, the attack vector is likely internal or requires compromised administrative credentials. The lack of listing in the CISA KEV catalog indicates no confirmed widespread exploitation to date, but the vulnerability still poses a notable risk if an attacker gains suitable access.

Generated by OpenCVE AI on September 3, 2026 at 10:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to the latest version that contains the security fix from Elastic.
  • Restrict Fleet write permissions to only trusted and verified users to limit the ability of low‑privileged accounts to initiate delete actions.
  • If the Fleet feature is not required, temporarily disable or remove it from the Kibana deployment.

Generated by OpenCVE AI on September 3, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Thu, 03 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.
Title Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T15:58:11.954Z

Reserved: 2026-08-24T21:13:51.299Z

Link: CVE-2026-78599

cve-icon Vulnrichment

Updated: 2026-09-02T15:50:39.697Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T15:17:41.003

Modified: 2026-09-03T13:43:00.447

Link: CVE-2026-78599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')