CVE-2026-33466
Elastic Logstash, logstash
Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed archives. An attacker who can serve a specially crafted archive to Logstash through a compromised or attacker-controlled update endpoint can write arbitrary files to the host filesystem with the privileges of the Logstash process. In certain configurations where automatic pipeline reloading is enabl...
- CVSS
- 9.8
- EPSS
- 0.55% 42.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.09