Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-49093

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.2%
CVSS Severity
CVSS v3 Score 6.3
Products affected by CVE-2026-49093
  • Elastic » Kibana » Version: 9.3.0
    cpe:2.3:a:elastic:kibana:9.3.0
  • Elastic » Kibana » Version: 9.3.2
    cpe:2.3:a:elastic:kibana:9.3.2


Contact Us

Shodan ® - All rights reserved