CVE-2026-26938: Elastic Kibana

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.

Affected products

Published 2026-02-26. Last modified 2026-06-17.