PT-2026-22172 · Elastic · Kibana

Ismisepaul

+1

·

Published

2026-02-26

·

Updated

2026-03-03

·

CVE-2026-26938

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description An issue exists in Kibana Workflows related to improper neutralization of special elements used in a template engine (CWE-1336). This could allow an authenticated attacker with the workflowsManagement:executeWorkflow privilege to read arbitrary files from the Kibana server filesystem and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). The vulnerability requires an authenticated user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-26938
BIT-KIBANA-2026-26938
CVE-2026-26938

Affected Products

Kibana