Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.
{
"cna_assigner": "elastic",
"cwe_ids": [
"CWE-918"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42398.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "9.3.0"
},
{
"last_affected": "9.3.1"
},
{
"introduced": "9.0.0"
},
{
"last_affected": "9.2.7"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42398.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "313541444604022866958265865213287872231",
"length": 2564
},
"id": "CVE-2026-42398-06197982",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
"target": {
"file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java",
"function": "testInfer_HandlesRerankRequest_Cohere_Format"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"156160656205353710312417330007629646425",
"27540708710486173236890240881820799260",
"84518175777564430454801298513242619573",
"136402608114113847601090415034067017773",
"16685559839112528659657881848863245510",
"277835739336649128433308394271788756561",
"143403250630798963826979644229512419723",
"242980579120754426761278468243787446353",
"321462624435310913302967518806687950974",
"82440798655824113832413828047961730518",
"300548741379807994336286196384108730640",
"256779652660472638210534763824804187552",
"46222788890441027068999511612152366503",
"48937933508108699071176309781932746930",
"321970245818726015799678340334047054700",
"172739829844646851416045766878270726607",
"153181888051955665546337367444036365656",
"124203616535444030273644361170629356875",
"100288444706359222937913017399433232159",
"309121548608204327250789539063946789326",
"319438141153746998409517777182091138336",
"51255505636426694297194044976326173232",
"250231542314301263066514395393284450737",
"214203989972935641826654681659282859419",
"58571146959237865627308032052375046049",
"47803809438137473017466825957232440899",
"336707179944840764682142298537860500446",
"45359245951768277319030149077281059574",
"58571146959237865627308032052375046049",
"162652334313199734502565521188201841382",
"175189539859557767461718357888782510477",
"165061306684265803088016931257610841584",
"58571146959237865627308032052375046049",
"69162281990582052467731627710640533493",
"128362147427298691431615098578884100365",
"270868705285420681643886908449567876922",
"287349046153840999809432690173922512964",
"294854095830598145422475187835678140215",
"68466100780771457268999999727315104566",
"95631642600171755226656183773782482039",
"229654468484481408976566219960030671636",
"64548248078566969071175771176786188803",
"191647534389363118453993355167357423246",
"146902999317757780523486174473002567414"
],
"threshold": 0.9
},
"id": "CVE-2026-42398-1b19fcf4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
"target": {
"file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"235127462228297284959627011147384431967",
"63416698433777538727099695573337933982",
"292855198434400605051192605274545575878",
"67872330018420459796311863072116526347",
"175773279971023045532788344412093721823",
"184184491137811567630774351126349740331",
"208384035772505989315956516357077240404",
"141253461345257827617096098816021767159"
],
"threshold": 0.9
},
"id": "CVE-2026-42398-5b18504a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
"target": {
"file": "x-pack/plugin/inference/src/main/java/org/elasticsearch/xpack/inference/services/custom/CustomService.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "315262054749030809412106802625080574319",
"length": 450
},
"id": "CVE-2026-42398-5ba38e01",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
"target": {
"file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java",
"function": "createCustomModel"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"47078404655310713527206886804508652819",
"9736821135205453259684021960045915104",
"321479224129948038347422783508630426551",
"336929828005760250217549392973710757538",
"87981632530719927991976872050798427068",
"241140473887075321789748749310666516124",
"296709739770584752465477459733490979822"
],
"threshold": 0.9
},
"id": "CVE-2026-42398-6bc40983",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/43a703737aab6baefa748bc7b69e4054926f2b2c",
"target": {
"file": "server/src/test/java/org/elasticsearch/index/query/PrefixQueryBuilderTests.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "37021890429624638425557029306735886735",
"length": 1912
},
"id": "CVE-2026-42398-d1e131ba",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
"target": {
"file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java",
"function": "testInfer_HandlesSparseEmbeddingRequest_Alibaba_Format"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "228013337158870705279216444561884658301",
"length": 226
},
"id": "CVE-2026-42398-e3ef07c4",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
"target": {
"file": "x-pack/plugin/inference/src/main/java/org/elasticsearch/xpack/inference/services/custom/CustomService.java",
"function": "extractPersistentChunkingSettings"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "41092078304446841000783939087813094753",
"length": 1721
},
"id": "CVE-2026-42398-e7a4c834",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
"target": {
"file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java",
"function": "testInfer_HandlesCompletionRequest_OpenAI_Format"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "107649075361093097895479135995297736263",
"length": 292
},
"id": "CVE-2026-42398-e8da0d97",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/43a703737aab6baefa748bc7b69e4054926f2b2c",
"target": {
"file": "server/src/test/java/org/elasticsearch/index/query/PrefixQueryBuilderTests.java",
"function": "testPrefixCircuitBreakerTripsWithLowLimit"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "326665976071484658195152997738423757368",
"length": 691
},
"id": "CVE-2026-42398-ec6b2be0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
"target": {
"file": "x-pack/plugin/inference/src/main/java/org/elasticsearch/xpack/inference/services/custom/CustomService.java",
"function": "parseRequestConfig"
}
}
]
"2026-08-12T16:25:14Z"