HIGHVulnerability

CVE-2026-72677

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.

Properties

severity
HIGH
score
7.3
epss_score
0.00278
cve_id
CVE-2026-72677
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
published_at
2026-08-13T20:17:28.373
last_modified
2026-09-02T14:09:48.843
epss_percentile
0.19911

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Relative Path Traversal

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72677 — Ninja Signal Threat Intelligence | Ninja Signal