CVE-2026-49088 Details
Description
Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may be accessible to operators with log access.
A vulnerability exists in Elastic Kibana versions 8.0.0 prior to 8.18.8, 8.19.0 prior to 8.19.5, 9.0.0 prior to 9.0.7, and 9.1.0 prior to 9.1.5. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values, including Cookie information, could be inadvertently logged in application logs. This information may be accessible to operators with log access, leading to potential information disclosure.
Users can upgrade to Kibana versions 8.18.9, 8.19.6, 9.0.8, or 9.1.6 to address this vulnerability. For users who cannot upgrade, it is recommended to disable the optional APM instrumentation until the deployment can be upgraded. This vulnerability has already been remediated in Elastic Cloud Serverless offerings.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/kibana-8-18-9-8-19-6-9-0-8-9-1-6-security-update-esa-2026-50 | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 8.0.0, < 8.18.9 >= 8.19.0, < 8.19.6 >= 9.0.0, < 9.0.8 >= 9.1.0, < 9.1.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |