HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-33458 — Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to informa...

·Source: NIST NVD

Updated:

Executive Summary

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

Analysis

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data. CVSS Score: 6.3. Published: 2026-04-08T18:26:00.267.

Indicators of Compromise (1)

CVE (1)
CVE-2026-33458
Source Attribution

Originally published by NIST NVD on Apr 8, 2026. Verified by: NIST.

Related Threats