CVE-2026-72677
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139)
CVSS
7.3
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 13 ago 2026 · Última mod.: 13 ago 2026 · CWE-23
Sin historial EPSS suficiente todavía.
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-162309.8 CRÍ40.1%
——12The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.2dCVE-2026-703378.8 ALT52.6%
——16Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.6hCVE-2026-658107.8 ALT28.0%
——8Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.8hCVE-2026-628376.5 MED53.2%
——16Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.3dCVE-2026-534167.1 ALT6.7%
——2Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.3dCVE-2026-160538.5 ALT59.4%
——18Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.3d