CVETodo[verified]@CveTodoGeneral
The post announces CVE‑2026‑26938, a Kibana Workflow template engine flaw that can lead to remote code execution for authenticated users, but provides no PoC, exploit, or patch details.
Autumn Good@autumn_good_35Patch
The advisory announces a Kibana 9.3.1 security update for CVE-2026-26938, describing a SSRF vulnerability and indicating a patch is available.
CVEFind.com@CveFindComDisclosure
The post announces a high‑severity vulnerability in Kibana Workflows that allows authenticated users with executeWorkflow privilege to read files and perform SSRF via code injection.
CERT-PY@CERTpyGeneral
The post alerts to CVE-2026-26938, offering a link for further information but lacks details on exploits, patches, or technical aspects.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE‑2026‑26938, a high‑severity template engine vulnerability in Kibana’s workflows, providing CVSS score and CWE reference, but offers no PoC, exploit, or patch details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text references a new vulnerability (CVE-2026-26938) involving SSRF and code injection in Kibana Workflows Management, but provides no details on PoC, exploit, patch, or active exploitation.
The Hacker Wire@TheHackerWireDisclosure
The post announces CVE-2026-26938, a high‑severity flaw in Kibana’s workflow template engine that permits arbitrary file reads from the server.
CVE@CVEnewDisclosure
The CVE‑2026‑26938 vulnerability in Kibana’s Workflows allows attackers to read arbitrary files due to improper neutralization of template engine elements.