Security Advisory

CVE-2026-26938

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-26 17:56:48
Last updated 2026-02-27 16:03:59
Assigner elastic
State PUBLISHED

Description

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who has the workflowsManagement:executeWorkflow privilege.