Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic kibana |
|
| Vendors & Products |
Elastic
Elastic kibana |
|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed. | |
| Title | Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-08-13T20:31:50.086Z
Reserved: 2026-08-10T11:17:49.704Z
Link: CVE-2026-72677
Updated: 2026-08-13T20:31:46.099Z
Status : Received
Published: 2026-08-13T20:17:28.373
Modified: 2026-08-13T21:18:12.443
Link: CVE-2026-72677
No data.
OpenCVE Enrichment
Updated: 2026-08-13T21:15:02Z
-
CWE-23
Relative Path Traversal