AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72677

HIGH · CVSS 7.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Kibana is vulnerable to a relative path traversal flaw that allows attackers to manipulate user-supplied identifiers, potentially leading to unauthorized deletion of Kibana resources. This vulnerability poses a significant risk to organizations using Kibana for data visualization and analysis, as it can compromise the integrity of their configurations. Users of Kibana, especially those managing Fleet Server host configurations, should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-72677
Severity
HIGH
CVSS
7.3
EPSS
0.27%

Original NVD Description

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.