---
cve: "CVE-2026-0532"
severity: "HIGH"
cvss: 8.6
epss: "43%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-01-14 11:15:50"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T16:54:53+02:00"
---

# CVE-2026-0532

> 8.6 HIGH

## Beschreibung

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-73** — External Control of File Name or Path
  The product allows user input to control or influence paths or file names that are used in filesystem operations.
- **CWE-918** — Server-Side Request Forgery (SSRF)
  The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

## Angriffsmuster (CAPEC)

- [CAPEC-13 — Subverting Environment Variable Values](https://capec.mitre.org/data/definitions/13.html) _(Severity: Very High)_
- [CAPEC-64 — Using Slashes and URL Encoding Combined to Bypass Validation Logic](https://capec.mitre.org/data/definitions/64.html) _(Severity: High)_
- [CAPEC-72 — URL Encoding](https://capec.mitre.org/data/definitions/72.html) _(Severity: High)_
- [CAPEC-76 — Manipulating Web Input to File System Calls](https://capec.mitre.org/data/definitions/76.html) _(Severity: Very High)_
- [CAPEC-78 — Using Escaped Slashes in Alternate Encoding](https://capec.mitre.org/data/definitions/78.html) _(Severity: High)_
- [CAPEC-79 — Using Slashes in Alternate Encoding](https://capec.mitre.org/data/definitions/79.html) _(Severity: High)_
- [CAPEC-80 — Using UTF-8 Encoding to Bypass Validation Logic](https://capec.mitre.org/data/definitions/80.html) _(Severity: High)_
- [CAPEC-267 — Leverage Alternate Encoding](https://capec.mitre.org/data/definitions/267.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1562.003 — Impair Defenses:Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
- [T1574.006 — Hijack Execution Flow:Dynamic Linker Hijacking](https://attack.mitre.org/techniques/T1574/006/)
- [T1574.007 — Hijack Execution Flow:Path Interception by PATH Environment ](https://attack.mitre.org/techniques/T1574/007/)
- [T1027 — Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027/)

## Referenzen

- <https://discuss.elastic.co/t/kibana-8-19-10-9-1-10-9-2-4-security-update-esa-2026-05/384524>
- <https://access.redhat.com/security/cve/CVE-2026-0532>
- <https://bugzilla.redhat.com/show_bug.cgi?id=2429540>
- <https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0532.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-0532) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
