CVE-2026-33458 - CERT CVE
ID CVE-2026-33458
Sažetak Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.
Reference
CVSS
Base: 6.3
Impact: 4.0
Exploitability:1.8
Pristup
VektorSloženostAutentikacija
NETWORK HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH NONE NONE
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Zadnje važnije ažuriranje 13-04-2026 - 11:30
Objavljeno 08-04-2026 - 18:26