CVE-2026-33462 Details
Description
A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifier. When an administrator subsequently attempts to delete this dashboard through the Kibana interface, the deletion request is redirected to an unintended internal endpoint, potentially resulting in the unauthorized deletion of user accounts or other resources. Exploitation requires an administrator to perform a delete action on the maliciously crafted dashboard object.
A path traversal vulnerability exists in Kibana's dashboard management feature. It allows an authenticated user with limited permissions to create a dashboard using a specially crafted identifier. When an administrator tries to delete this dashboard, the request is mistakenly sent to an internal endpoint, which could lead to the unauthorized deletion of user accounts or other resources. This vulnerability affects Kibana versions 8.0.0 through 8.19.15 and 9.0.0 through 9.3.4.
Users can upgrade to Kibana versions 8.19.16 or 9.3.5, where this vulnerability has been fixed. For those unable to upgrade, it is recommended to restrict dashboard creation permissions to trusted users only and limit the dashboard deletion rights of administrators.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/kibana-8-19-16-and-9-3-5-security-update-esa-2026-30/386545 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 8.0.0, < 8.19.16 >= 9.0.0, < 9.3.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | [email protected] |