ElasticCVE-2026-78602
Elastic Maps Server: path traversal
Medium5.3CVE-2026-78602 · Published Sep 2, 2026 · updated Sep 8, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Elastic Maps Server Product | >= 8.19.11, <= 8.19.18 | No fix yet |
| >= 9.3.0, <= 9.4.3 | No fix yet | |
| <= 9.5.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-22
More Elastic advisories
All Elastic| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Elastic Kibana: improper authorization | Medium4.3 | No fix yet |
| Sep 2 | Elastic Kibana: path traversal | Medium6.5 | No fix yet |
| Sep 2 | Elastic Eck Operator: incomplete cleanup | Low3.5 | No fix yet |
| Sep 2 | Elastic Kibana: missing authorization | Medium5.5 | No fix yet |
| Sep 2 | Elastic Agent: insecure permissions | High7.8 | No fix yet |
| Sep 2 | Elastic Eck Operator: improper authorization | Medium5.4 | No fix yet |