---
cve: "CVE-2026-49088"
severity: "MEDIUM"
cvss: 4.4
epss: "21%"
vendor: "Elastic"
kev: false
exploited: false
published: "2026-07-01 17:16:35"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T15:21:49+02:00"
---

# CVE-2026-49088

> 4.4 MEDIUM

## Beschreibung

Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may be accessible to operators with log access.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-532** — Insertion of Sensitive Information into Log File
  The product writes sensitive information to a log file.

## Angriffsmuster (CAPEC)

- [CAPEC-215 — Fuzzing for application mapping](https://capec.mitre.org/data/definitions/215.html) _(Severity: Low)_

## Patch verfügbar (OSV)

- d2c42d91a1eb9e14b1a37c4d87eb2533ec859e2b (Commit)
- 936f7cf370e0d7952bb71a98629284c3c0e0d00e (Commit)

## Referenzen

- <https://discuss.elastic.co/t/kibana-8-18-9-8-19-6-9-0-8-9-1-6-security-update-esa-2026-50>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-49088) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
