CVE-2026-42401 Affecting kibana-9.0 package, versions *


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-MINIMOSLATEST-KIBANA90-17247620
  • published9 Jun 2026
  • disclosed28 May 2026

Introduced: 28 May 2026

NewCVE-2026-42401  (opens in a new tab)

How to fix?

There is no fixed version for Minimos:latest kibana-9.0.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kibana-9.0 package and not the kibana-9.0 package as distributed by Minimos. See How to fix? for Minimos:latest relevant fixed versions and status.

Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user, was not sufficiently sanitized. Successful exploitation could result in unauthorized UI manipulation and outbound network requests issued from the viewing user's browser session.

CVSS Base Scores

version 3.1