Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-72677

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.

EPSS

Процентиль: 20%
0.00272
Низкий

7.3 High

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 7.3
debian
5 дней назад

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorize ...

CVSS3: 7.3
github
5 дней назад

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.

EPSS

Процентиль: 20%
0.00272
Низкий

7.3 High

CVSS3

Дефекты

CWE-23