CVE-2026-0532: External Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Gemini Connector
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0532?
CVE-2026-0532 is considered a critical vulnerability due to its potential for arbitrary file disclosure and server-side request forgery.
How do I fix CVE-2026-0532?
To fix CVE-2026-0532, upgrade to the latest version of Elastic Kibana that includes the security patch.
What are the impacts of CVE-2026-0532?
The impacts of CVE-2026-0532 include unauthorized access to sensitive files and the ability for attackers to exploit server-side request forgery vulnerabilities.
Which versions of Kibana are affected by CVE-2026-0532?
CVE-2026-0532 affects certain earlier versions of Elastic Kibana prior to the security update.
Is there a workaround for CVE-2026-0532 until a patch is applied?
Currently, the recommended course of action is to apply the provided security patch rather than rely on workarounds for CVE-2026-0532.