CVE-2026-26938 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary f…
High CVSS: 8.6

CVE-2026-26938

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.
Vendor
Elastic
Product
Kibana
CWE
CWE-1336
Yayın Tarihi
2026-02-26 19:32:39
Güncelleme
2026-03-02 15:40:36
Source Identifier
security@elastic.co
KEV Date Added
-

Kategoriler

Referanslar