Vulnerability Details CVE-2026-49093
Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to block.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.8%
CVSS Severity
CVSS v3 Score 6.3
Products affected by CVE-2026-49093
-
cpe:2.3:a:elastic:kibana:9.3.0
-
cpe:2.3:a:elastic:kibana:9.3.2