---
cve: "CVE-2026-42398"
severity: "HIGH"
cvss: 7.7
epss: "0.3%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-05-28 19:47:53"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-25T01:59:37+02:00"
---

# CVE-2026-42398

> 7.7 HIGH

## Beschreibung

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-918** — Server-Side Request Forgery (SSRF)
  The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

## Angriffsmuster (CAPEC)

- [CAPEC-664 — Server Side Request Forgery](https://capec.mitre.org/data/definitions/664.html) _(Severity: High)_

## Patch verfügbar (OSV)

- cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1 (Commit)
- 43a703737aab6baefa748bc7b69e4054926f2b2c (Commit)

## Referenzen

- <https://discuss.elastic.co/t/kibana-9-2-8-and-9-3-2-security-update-esa-2026-37/386557>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-42398) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
