CVE-2026-72677
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
- EPSS probability
- 0.28%
- CWE
- CWE-23
- Published
- 2026-08-13
- Last modified
- 2026-08-13
Affected products
- Elastic Kibana
- Elastic Kibana
- Elastic Kibana
Weakness type
Related vulnerabilities
- CVE-2026-84939 — Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks
- CVE-2026-15913 — Path Traversal in Fortra's GoAnywhere MFT Endpoint
- CVE-2026-79728 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87747 — Ragic|Enterprise Cloud Database - Arbitrary File Read
- CVE-2026-47680 — Source controller: Improper path handling allows traversal
- CVE-2026-77897 — Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
- CVE-2026-72948 — Windows DNS Elevation of Privilege Vulnerability
- CVE-2026-67367 — A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE...