Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-26938

Опубликовано: 26 фев. 2026
Источник: nvd
CVSS3: 8.6
CVSS3: 7.7
EPSS Низкий

Описание

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:kibana:9.3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 16%
0.0005
Низкий

8.6 High

CVSS3

7.7 High

CVSS3

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 8.6
debian
около 1 месяца назад

Improper Neutralization of Special Elements Used in a Template Engine ...

CVSS3: 8.6
github
около 1 месяца назад

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.

EPSS

Процентиль: 16%
0.0005
Низкий

8.6 High

CVSS3

7.7 High

CVSS3

Дефекты

CWE-1336