Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-49093

Опубликовано: 28 мая 2026
Источник: nvd
CVSS3: 6.3
CVSS3: 7.7
EPSS Низкий

Описание

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
Версия от 9.3.0 (включая) до 9.3.3 (исключая)

EPSS

Процентиль: 10%
0.00199
Низкий

6.3 Medium

CVSS3

7.7 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.3
debian
2 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana can allow an authentic ...

CVSS3: 6.3
github
2 месяца назад

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.

EPSS

Процентиль: 10%
0.00199
Низкий

6.3 Medium

CVSS3

7.7 High

CVSS3

Дефекты

CWE-918