# CVE-2026-0532

## Summary

- **CVE ID:** CVE-2026-0532
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-918
- **Published:** Jan 14, 2026
- **Last Modified:** Sep 14, 2026

## Description

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.

## Affected Products

- Elastic — Kibana (8.15.0)
- Elastic — Kibana (9.0.0)
- Elastic — Kibana (9.2.0)

## References

- [CNA](https://discuss.elastic.co/t/kibana-8-19-10-9-1-10-9-2-4-security-update-esa-2026-05/384524)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-0532)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2429540)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0532.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 40.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._