CVE-2026-42398

Source
https://cve.org/CVERecord?id=CVE-2026-42398
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42398.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42398
Aliases
Downstream
Published
2026-05-28T19:47:53Z
Modified
2026-08-12T16:25:14Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access
Details

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.

Database specific
{
    "cna_assigner": "elastic",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42398.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "9.3.0"
                },
                {
                    "last_affected": "9.3.1"
                },
                {
                    "introduced": "9.0.0"
                },
                {
                    "last_affected": "9.2.7"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.2.8"
        },
        {
            "introduced": "9.3.0"
        },
        {
            "fixed": "9.3.2"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v9.*
v9.3.0
v9.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42398.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "313541444604022866958265865213287872231",
            "length": 2564
        },
        "id": "CVE-2026-42398-06197982",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
        "target": {
            "file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java",
            "function": "testInfer_HandlesRerankRequest_Cohere_Format"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "156160656205353710312417330007629646425",
                "27540708710486173236890240881820799260",
                "84518175777564430454801298513242619573",
                "136402608114113847601090415034067017773",
                "16685559839112528659657881848863245510",
                "277835739336649128433308394271788756561",
                "143403250630798963826979644229512419723",
                "242980579120754426761278468243787446353",
                "321462624435310913302967518806687950974",
                "82440798655824113832413828047961730518",
                "300548741379807994336286196384108730640",
                "256779652660472638210534763824804187552",
                "46222788890441027068999511612152366503",
                "48937933508108699071176309781932746930",
                "321970245818726015799678340334047054700",
                "172739829844646851416045766878270726607",
                "153181888051955665546337367444036365656",
                "124203616535444030273644361170629356875",
                "100288444706359222937913017399433232159",
                "309121548608204327250789539063946789326",
                "319438141153746998409517777182091138336",
                "51255505636426694297194044976326173232",
                "250231542314301263066514395393284450737",
                "214203989972935641826654681659282859419",
                "58571146959237865627308032052375046049",
                "47803809438137473017466825957232440899",
                "336707179944840764682142298537860500446",
                "45359245951768277319030149077281059574",
                "58571146959237865627308032052375046049",
                "162652334313199734502565521188201841382",
                "175189539859557767461718357888782510477",
                "165061306684265803088016931257610841584",
                "58571146959237865627308032052375046049",
                "69162281990582052467731627710640533493",
                "128362147427298691431615098578884100365",
                "270868705285420681643886908449567876922",
                "287349046153840999809432690173922512964",
                "294854095830598145422475187835678140215",
                "68466100780771457268999999727315104566",
                "95631642600171755226656183773782482039",
                "229654468484481408976566219960030671636",
                "64548248078566969071175771176786188803",
                "191647534389363118453993355167357423246",
                "146902999317757780523486174473002567414"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-42398-1b19fcf4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
        "target": {
            "file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "235127462228297284959627011147384431967",
                "63416698433777538727099695573337933982",
                "292855198434400605051192605274545575878",
                "67872330018420459796311863072116526347",
                "175773279971023045532788344412093721823",
                "184184491137811567630774351126349740331",
                "208384035772505989315956516357077240404",
                "141253461345257827617096098816021767159"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-42398-5b18504a",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
        "target": {
            "file": "x-pack/plugin/inference/src/main/java/org/elasticsearch/xpack/inference/services/custom/CustomService.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "315262054749030809412106802625080574319",
            "length": 450
        },
        "id": "CVE-2026-42398-5ba38e01",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
        "target": {
            "file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java",
            "function": "createCustomModel"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "47078404655310713527206886804508652819",
                "9736821135205453259684021960045915104",
                "321479224129948038347422783508630426551",
                "336929828005760250217549392973710757538",
                "87981632530719927991976872050798427068",
                "241140473887075321789748749310666516124",
                "296709739770584752465477459733490979822"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-42398-6bc40983",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/43a703737aab6baefa748bc7b69e4054926f2b2c",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/index/query/PrefixQueryBuilderTests.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "37021890429624638425557029306735886735",
            "length": 1912
        },
        "id": "CVE-2026-42398-d1e131ba",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
        "target": {
            "file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java",
            "function": "testInfer_HandlesSparseEmbeddingRequest_Alibaba_Format"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "228013337158870705279216444561884658301",
            "length": 226
        },
        "id": "CVE-2026-42398-e3ef07c4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
        "target": {
            "file": "x-pack/plugin/inference/src/main/java/org/elasticsearch/xpack/inference/services/custom/CustomService.java",
            "function": "extractPersistentChunkingSettings"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "41092078304446841000783939087813094753",
            "length": 1721
        },
        "id": "CVE-2026-42398-e7a4c834",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
        "target": {
            "file": "x-pack/plugin/inference/src/test/java/org/elasticsearch/xpack/inference/services/custom/CustomServiceTests.java",
            "function": "testInfer_HandlesCompletionRequest_OpenAI_Format"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "107649075361093097895479135995297736263",
            "length": 292
        },
        "id": "CVE-2026-42398-e8da0d97",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/43a703737aab6baefa748bc7b69e4054926f2b2c",
        "target": {
            "file": "server/src/test/java/org/elasticsearch/index/query/PrefixQueryBuilderTests.java",
            "function": "testPrefixCircuitBreakerTripsWithLowLimit"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "326665976071484658195152997738423757368",
            "length": 691
        },
        "id": "CVE-2026-42398-ec6b2be0",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/elastic/elasticsearch/commit/cdb2d7a7a46dfe4ef7c3f859b94fb86ba8e652e1",
        "target": {
            "file": "x-pack/plugin/inference/src/main/java/org/elasticsearch/xpack/inference/services/custom/CustomService.java",
            "function": "parseRequestConfig"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:25:14Z"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.2.8"
        },
        {
            "introduced": "9.3.0"
        },
        {
            "fixed": "9.3.2"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v9.*
v9.3.0
v9.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42398.json"