CVE-2026-33466Disclosure(elastic / logstash)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch elastic logstash systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed archives. An attacker who can serve a specially crafted archive to Logstash through a compromised or attacker-controlled update endpoint can write arbitrary files to the host filesystem with the privileges of the Logstash process. In certain configurations where automatic pipeline reloading is enabled, this can be escalated to remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • logstash

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-08); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
logstash

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-08: 1Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-10: 104-0804-1004-1104-13
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-081
Disclosure1
2026-04-101
Patch1
2026-04-111
Disclosure1
2026-04-131
General1
Full discourse4 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Elastic ❗ CVE-2026-4498 ❗ CVE-2026-33466 ❗ CVE-2026-33461 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-elastic-2/ https://t.co/9mpmyikW4w

    Post summary

    The post lists three Elastic product CVEs and points to an external link for more detail, but provides no specific vulnerability data, exploit, or remediation information.

    00020123
    6.6K followersView on X
  • ✨_geeknik_//✨@geeknik
    Disclosure

    I'm the original reporter of the Logstash CVE-2026-33466 bug. 😎 https://discuss.elastic.co/t/logstash-8-19-14-9-2-8-9-3-3-security-update-esa-2026-29/385816

    Post summary

    The user declares themselves as the original reporter of Logstash CVE‑2026‑33466, but provides no further technical details or evidence of exploitation.

    00011241
    20.1K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『In certain configurations where automatic pipeline reloading is enabled, this can be escalated to remote code execution.』 CVE-2026-33466 Logstash 8.19.14, 9.2.8, 9.3.3 Security Update (ESA-2026-29) https://discuss.elastic.co/t/logstash-8-19-14-9-2-8-9-3-3-security-update-esa-2026-29/385816

    Post summary

    CVE-2026-33466 in Logstash can lead to remote code execution in specific configurations, and a security update (ESA-2026-29) addresses the issue.

    00020873
    6.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33466 Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative P… https://www.cve.org/CVERecord?id=CVE-2026-33466

    Post summary

    The CVE record outlines a pathname traversal flaw in Logstash that could enable arbitrary file writes and remote code execution, but no PoC, exploit, or patch information is provided.

    00000119
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelasticlogstash---

Explore more