PatchSiren cyber security CVE debrief
CVE-2026-72677 Elastic CVE debrief
CVE-2026-72677 is a Relative Path Traversal vulnerability in Kibana Fleet. The vulnerability exists because Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. These identifiers are stored as provided and later incorporated into requests when configurations are removed, potentially allowing attackers to manipulate these requests and lead to the unauthorized deletion of Kibana resources. Users of Kibana, particularly those using Fleet Server configurations, should be aware of this vulnerability. Administrators and security teams responsible for Kibana installations, especially in environments where Fleet is utilized, need to assess their exposure and apply necessary patches or mitigations. Affected versions include Kibana 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3. The CVE record was published on 2026-08-13T20:17:28.373Z and has not been modified since then. The NVD entry is currently Analyzed.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-02
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-02
Who should care
Users of Kibana, particularly those using Fleet Server configurations, should be aware of this vulnerability. Administrators and security teams responsible for Kibana installations, especially in environments where Fleet is utilized, need to assess their exposure and apply necessary patches or mitigations.
Technical summary
CVE-2026-72677 is a Relative Path Traversal vulnerability in Kibana. The vulnerability exists in the Kibana Fleet component, where user-supplied identifiers for Fleet Server host configurations are not properly sanitized, allowing for relative traversal sequences. This can lead to the unauthorized deletion of Kibana resources. The identifiers are stored as provided and later incorporated into requests when configurations are removed, potentially allowing attackers to manipulate these requests.
Defensive priority
Patch and verify Kibana configurations; restrict Fleet Server host configuration access.
Recommended defensive actions
- Apply vendor patches or updates to affected Kibana versions.
- Restrict access to Fleet Server host configuration management.
- Monitor for and respond to potential unauthorized resource deletion attempts.
- Verify and restrict the use of user-supplied identifiers in Kibana configurations.
- Review and update Kibana resource deletion procedures.
Evidence notes
The CVE-2026-72677 record indicates a Relative Path Traversal vulnerability in Kibana. Kibana Fleet accepted user-supplied identifiers for Fleet Server host configurations without rejecting relative traversal sequences. These identifiers are stored as provided and later used in requests when configurations are removed. Affected versions include Kibana 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72677 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72677
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72677 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72677
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-94/389512
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.