CVE-2026-42398

HIGH

Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access

Title source: cna
STIX 2.1

Description

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.

Scores

CVSS v3 7.7
EPSS 0.0027
EPSS Percentile 18.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (3)
Elastic/Kibana 9.0.0 - 9.2.7
elastic/kibana 9.0.0 - 9.2.8
Elastic/Kibana 9.3.0 - 9.3.1
Published May 28, 2026
Tracked Since May 29, 2026