CVE-2026-49091Disclosure(elastic / kibana)

LOWCVSS 8.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch elastic kibana systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently viewed in a terminal that interprets control sequences, the injected content may alter the displayed log data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kibana

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-07-01); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
kibana

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-01: 2Mentions · 2026-07-02: 1Mentions · 2026-07-13: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-02: 107-0107-0207-13
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-012
Disclosure1General1
2026-07-021
Patch1
2026-07-131
Disclosure1
Full discourse4 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Elastic ❗ CVE-2026-49091 ❗ CVE-2026-32283 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-elastic-4/ https://t.co/Qjp3pVsUu3

    Post summary

    The tweet lists two new Elastic CVEs (CVE-2026-49091, CVE-2026-32283) and points to a CERT website for further details, without providing exploits, patches, or technical specifics.

    00000208
    6.7K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2026-49091 Problem Type: CWE-117 - Improper Output Neutralization for Logs Impact: CAPEC-93 - Log Injection-Tampering-Forging Kibana 7.17.15, 8.11.1 Security Update (ESA-2026-53) - Announcements / Security Announcements https://discuss.elastic.co/t/kibana-7-17-15-8-11-1-security-update-esa-2026-53/387449

    Post summary

    Elastic announces a security update for Kibana (7.17.15, 8.11.1) addressing a log injection vulnerability (CWE-117), providing patch details and update link.

    00000637
    6.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49091 Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially… https://www.cve.org/CVERecord?id=CVE-2026-49091 ----- Traducción: CVE-2026-49091 Neu… http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE‑2026‑49091, a log injection weakness in Kibana, but it does not provide PoC code, exploit details, or patch information.

    0000028
    90 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-49091 Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially… https://www.cve.org/CVERecord?id=CVE-2026-49091

    Post summary

    The post outlines the technical details of CVE‑2026‑49091 in Kibana, indicating a log injection vulnerability, but it provides no PoC, exploit code, evidence of active exploitation, or patch information.

    00000810
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelastickibana---

Explore more