Elastic disclosed CVE-2026-26938, a high-severity (CVSS 8.6) issue in Kibana Workflows caused by improper neutralization of special elements in a template engine (CWE-1336). The flaw can enable code injection (CAPEC-242) that allows server-side request forgery (SSRF) and arbitrary file read from the Kibana server filesystem when the vulnerable workflow execution path is reached.
The issue is fixed in Kibana 9.3.1 (ESA-2026-17). Exploitation requires an authenticated user with the workflowsManagement:executeWorkflow privilege; the Workflows feature is off by default (technical preview in 9.3.0) and must be explicitly enabled in Advanced Settings, reducing exposure in default deployments. For organizations that cannot immediately upgrade, Elastic recommends disabling Workflows; Elastic also noted its Elastic Cloud Serverless offering was remediated prior to public disclosure under its continuous patching model.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Elastic published security advisory ESA-2026-21 announcing Kibana versions 8.19.14, 9.2.8, and 9.3.3. This is a new vendor security update disclosed after the earlier ESA-2026-17 advisory.
CVE-2026-26938 was publicly listed as an improper neutralization flaw in Kibana Workflows. The entry described the issue's impact, including arbitrary file read and SSRF, and referenced Elastic's ESA-2026-17 advisory.
Elastic published security advisory ESA-2026-17 announcing Kibana 9.3.1 to address CVE-2026-26938, a Kibana Workflows template engine flaw. The vulnerability could let an authenticated user with workflowsManagement:executeWorkflow privileges read arbitrary files and perform server-side request forgery via code injection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
discuss.elastic.co
Open sourcediscuss.elastic.co
Open sourcediscuss.elastic.co
Open sourcediscuss.elastic.co
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.