CVE-2026-49093: Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access
Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49093?
The severity of CVE-2026-49093 is medium with a score of 6.3.
How does CVE-2026-49093 affect Kibana?
CVE-2026-49093 allows an authenticated user to bypass allowed outbound network requests, enabling unauthorized access.
Who is impacted by CVE-2026-49093?
Authenticated users with connector management privileges in Kibana are impacted by CVE-2026-49093.
How can I mitigate the risk of CVE-2026-49093?
To mitigate CVE-2026-49093, ensure that proper access controls are enforced and restrict connector management privileges.
What type of vulnerability is CVE-2026-49093?
CVE-2026-49093 is classified as a Server-Side Request Forgery (SSRF) vulnerability.