CVE-2026-33458: Elastic Kibana

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

Affected products

  • Elastic Kibana: from 9.3.0, before 9.3.3 (fixed in 9.3.3)

Published 2026-04-08. Last modified 2026-07-24.