PT-2026-79958 · Bitnami · Kibana

Published

2026-08-19

·

Updated

2026-08-19

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-KIBANA-2026-72677

Affected Products

Kibana