CVE-2026-26938: Elastic Kibana
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.
Affected products
- Elastic Kibana: version 9.3.0 only
Published 2026-02-26. Last modified 2026-06-17.