PT-2026-44509 · Elastic · Kibana

Ismisepaul

+1

·

Published

2026-05-28

·

Updated

2026-06-01

·

CVE-2026-42398

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description Server-Side Request Forgery (SSRF) allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause the system to issue outbound requests to destinations that egress restriction controls were intended to block.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

BIT-ELK-2026-42398
BIT-KIBANA-2026-42398
CVE-2026-42398

Affected Products

Kibana