SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78591

MEDIUM · CVSS 6.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Kibana Fleet feature is vulnerable to a path traversal issue that allows low-privileged users to manipulate actions taken by higher-privileged users, potentially leading to unauthorized deletion of critical resources, including accounts with elevated privileges. Organizations utilizing Kibana should prioritize addressing this vulnerability to prevent potential exploitation that could compromise their resource management and security posture. Immediate attention is recommended for those with administrative interfaces exposed to low-privileged user interactions.

CVE
CVE-2026-78591
Severity
MEDIUM
CVSS
6.3
EPSS
0.23%

Original NVD Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.

Related CVEs

Other vulnerabilities affecting the same vendor(s)