CVE-2026-33458

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

13 Apr 2026, 11:30

Type Values Removed Values Added
First Time Elastic
Elastic kibana
CPE cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
References () https://discuss.elastic.co/t/kibana-9-3-3-security-update-esa-2026-28/385815 - () https://discuss.elastic.co/t/kibana-9-3-3-security-update-esa-2026-28/385815 - Vendor Advisory

08 Apr 2026, 18:26

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 18:26

Updated : 2026-04-13 11:30


NVD link : CVE-2026-33458

Mitre link : CVE-2026-33458

CVE.ORG link : CVE-2026-33458


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-918

Server-Side Request Forgery (SSRF)