CVE-2026-0532: Elastic Kibana

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.

Affected products

  • Elastic Kibana: from 8.15.0, up to and including 8.19.9; from 9.0.0, up to and including 9.1.9; from 9.2.0, up to and including 9.2.3
  • Red Hat Logging Subsystem For Red Hat Openshift
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
  • Red Hat Red Hat Openshift Distributed Tracing 3
  • Red Hat Red Hat Openstack Platform 16.2

Published 2026-01-14. Last modified 2026-07-15.