Sploitus

CVE-2026-33458

No indexed exploits for CVE-2026-33458 yet

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.

Affected products
Kibana
Elastic Kibana
< 9.3.3
CVSS 3.1
7.7 HIGH
EPSS
0.2% (13th percentile)
Weakness
CWE-918
NVD status
Analyzed
Published
2026-04-08
Attack patterns
CAPEC-664
CVE-2026-33458 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-33458 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-33458 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.