Report: Complete Guide to CVE-2026-42401 - Improper Neutralization of Input During Web Page Generation in Kibana Leading to...
CVE ID :CVE-2026-42401 Published : May 28, 2026, 7:40 p.m. | 41 minutes ago Description :Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user, was not sufficiently sanitized. Successful exploitation could result in unauthorized UI manipulation and outbound network requests issued from the viewing user's browser session. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
CWE-79