SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-78599

MEDIUM · CVSS 6.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-05

CyberRota Analysis

AI-Generated

The Kibana Fleet feature is vulnerable to a path traversal issue that allows low-privileged users with write access to potentially delete unintended internal resources. This vulnerability can be exploited if an administrator interacts with the affected Fleet interface, leading to unauthorized resource deletion. Organizations using Kibana should prioritize addressing this issue to mitigate the risk of accidental or malicious data loss.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78599
Severity
MEDIUM
CVSS
6.5
EPSS
0.31%

Original NVD Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.

Related CVEs

Other vulnerabilities affecting the same vendor(s)