CVE-2026-0532
Elastic Kibana, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform 8 취약점
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.
- 대응 우선순위
- 점검
- CVSS
- 8.6
- EPSS
- 0.42% 백분위 34.4% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.01.14