
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-72677 is a Relative Path Traversal vulnerability (CWE-23) in Elastic Kibana's Fleet component that allows authenticated attackers to delete arbitrary Kibana resources. Kibana Fleet accepts a user-supplied identifier for a Fleet Server host configuration without sanitizing relative traversal sequences (e.g., ../), which are stored as-is and later used in deletion requests. Affected versions include Kibana 8.0.0–8.19.16, 9.0.0–9.3.5, and 9.4.0–9.4.2. It was published on August 13, 2026, with a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Elastic Advisory).
The root cause is CWE-23 (Relative Path Traversal): Kibana Fleet does not validate or sanitize user-supplied Fleet Server host configuration identifiers before storing them. When the configuration is later deleted, the stored identifier — potentially containing sequences like ../ — is incorporated directly into the internal deletion request, allowing the path to resolve outside the intended resource scope (CAPEC-139). Exploitation requires low privileges (Fleet management access) and user interaction (triggering the deletion of the malicious configuration), making it a network-accessible but partially constrained attack vector (GitHub Advisory, Elastic Advisory).
Successful exploitation allows an authenticated attacker with Fleet management privileges to delete arbitrary Kibana resources — including critical configuration files, user accounts, and data — by crafting a malicious host identifier. There is no confidentiality impact (data is not exposed), but integrity and availability are both rated High, meaning attackers can cause significant disruption to Kibana operations and destroy important resources. The scope is unchanged, limiting direct lateral movement, but deletion of core configurations could destabilize dependent Elastic Stack components (GitHub Advisory, Elastic Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies the vulnerability as non-automatable with no known exploitation. The EPSS score is approximately 0.272%, placing it in the 20th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
../../target-resource) in the host identifier field.../, ..\, or URL-encoded equivalents (%2e%2e%2f); unexpected deletion events for Kibana resources (users, indices, configurations) correlated with Fleet configuration removal actions./api/fleet/fleet_server_hosts) with anomalous identifier values containing traversal sequences in request bodies.Elastic has released patched versions addressing this vulnerability: Kibana 8.19.17, 9.3.6, and 9.4.3. Users should upgrade to one of these versions as the primary remediation. As interim measures, restrict Fleet management privileges to only trusted administrators, and monitor Kibana audit logs for suspicious Fleet configuration operations involving path traversal patterns in host identifiers (Elastic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."