8.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Description
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.
AI Analysis
External Control of File Name or Path and Server-Side Request Forgery (SSRF) vulnerability in Kibana Google Gemini Connector
Basic Information
ID
CVE-2026-0532
Source
elastic
Published
Jan 14, 2026 at 10:14
Affected Product
Vendor
Elastic
Product
Kibana
Version
8.15.0
Affected Versions
Elastic Kibana 8.15.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Elastic
Product
Kibana
Version
8.15.0, 9.0.0, 9.2.0