CVE 4.1 MEDIUM

Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HTML Injection_CVE-2026-42401

4.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

Description

Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user, was not sufficiently sanitized. Successful exploitation could result in unauthorized UI manipulation and outbound network requests issued from the viewing user's browser session.

Basic Information

ID CVE-2026-42401
Source elastic
Published May 28, 2026 at 19:40

Affected Product

Vendor Elastic
Product Kibana
Version 9.0.0
Affected Versions Elastic Kibana 9.0.0
Elastic Kibana 8.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.