CVE-2026-0532: Elastic Kibana
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.
Affected products
- Elastic Kibana: from 8.15.0, up to and including 8.19.9; from 9.0.0, up to and including 9.1.9; from 9.2.0, up to and including 9.2.3
- Red Hat Logging Subsystem For Red Hat Openshift
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Red Hat Openshift Distributed Tracing 3
- Red Hat Red Hat Openstack Platform 16.2
Published 2026-01-14. Last modified 2026-07-15.