PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72677 Elastic CVE debrief

CVE-2026-72677 is a Relative Path Traversal vulnerability in Kibana Fleet. The vulnerability exists because Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. These identifiers are stored as provided and later incorporated into requests when configurations are removed, potentially allowing attackers to manipulate these requests and lead to the unauthorized deletion of Kibana resources. Users of Kibana, particularly those using Fleet Server configurations, should be aware of this vulnerability. Administrators and security teams responsible for Kibana installations, especially in environments where Fleet is utilized, need to assess their exposure and apply necessary patches or mitigations. Affected versions include Kibana 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3. The CVE record was published on 2026-08-13T20:17:28.373Z and has not been modified since then. The NVD entry is currently Analyzed.

Vendor
Elastic
Product
Kibana
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-02
Advisory published
2026-08-13
Advisory updated
2026-09-02

Who should care

Users of Kibana, particularly those using Fleet Server configurations, should be aware of this vulnerability. Administrators and security teams responsible for Kibana installations, especially in environments where Fleet is utilized, need to assess their exposure and apply necessary patches or mitigations.

Technical summary

CVE-2026-72677 is a Relative Path Traversal vulnerability in Kibana. The vulnerability exists in the Kibana Fleet component, where user-supplied identifiers for Fleet Server host configurations are not properly sanitized, allowing for relative traversal sequences. This can lead to the unauthorized deletion of Kibana resources. The identifiers are stored as provided and later incorporated into requests when configurations are removed, potentially allowing attackers to manipulate these requests.

Defensive priority

Patch and verify Kibana configurations; restrict Fleet Server host configuration access.

Recommended defensive actions

  • Apply vendor patches or updates to affected Kibana versions.
  • Restrict access to Fleet Server host configuration management.
  • Monitor for and respond to potential unauthorized resource deletion attempts.
  • Verify and restrict the use of user-supplied identifiers in Kibana configurations.
  • Review and update Kibana resource deletion procedures.

Evidence notes

The CVE-2026-72677 record indicates a Relative Path Traversal vulnerability in Kibana. Kibana Fleet accepted user-supplied identifiers for Fleet Server host configurations without rejecting relative traversal sequences. These identifiers are stored as provided and later used in requests when configurations are removed. Affected versions include Kibana 8.0.0 to 8.19.17, 9.0.0 to 9.3.6, and 9.4.0 to 9.4.3.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72677 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72677

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72677 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72677

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-94/389512

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.