CVE-2026-72677: Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72677?
The severity of CVE-2026-72677 is rated as high with a score of 7.3.
How does CVE-2026-72677 affect Kibana?
CVE-2026-72677 allows for unauthorized deletion of users and resources in Kibana due to a relative path traversal vulnerability.
What systems are impacted by CVE-2026-72677?
CVE-2026-72677 specifically impacts Kibana when the Fleet Server host configuration is improperly handled.
How do I fix CVE-2026-72677?
To fix CVE-2026-72677, update Kibana to the latest version where the vulnerability has been addressed.
What is the risk associated with CVE-2026-72677?
CVE-2026-72677 poses a risk score of 54, indicating a high potential for security threats related to unauthorized resource manipulations.