Vulnerability record · CVE-2018-17246 · published 20 December 2018
CVE-2018-17246: Kibana Console plugin arbitrary file inclusion enables code execution
Elastic · Kibana
Kibana before 6.4.3 and 5.6.13 contains an arbitrary file inclusion flaw in the Console plugin. A request to the Console API can cause JavaScript code to be executed, potentially leading to arbitrary command execution with the privileges of the Kibana process. The flaw is remotely reachable without authentication or user interaction per the CVSS vector, making it a serious exposure for internet-facing Kibana instances.
Description
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction required, and a very high EPSS score make this a top-priority patch.
What it is
Kibana before 6.4.3 and 5.6.13 contains an arbitrary file inclusion flaw in the Console plugin. A request to the Console API can cause JavaScript code to be executed, potentially leading to arbitrary command execution with the privileges of the Kibana process. The flaw is remotely reachable without authentication or user interaction per the CVSS vector, making it a serious exposure for internet-facing Kibana instances.
Impact
An attacker can execute arbitrary commands on the host with the permissions of the Kibana process, compromising the Kibana server and any data or credentials it can reach.
Attack surface
Reached over the network through the Kibana Console API; the CVSS vector indicates no authentication and no user interaction are required, though the description notes the attacker needs access to the Console API.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.82251, 99.64th percentile), indicating strong likelihood of exploitation activity. References are vendor and third-party advisories only, with no public exploit tag supplied.
What to do
- Upgrade Kibana to 6.4.3 or 5.6.13 (or later) as directed by the Elastic security advisory.
- If immediate upgrade is not possible, restrict network access to the Kibana Console API and the Kibana service to trusted hosts only.
- Run Kibana with a least-privilege service account and isolate it from sensitive hosts and data.
- Apply the Red Hat errata RHBA-2018:3743 for affected OpenShift Container Platform deployments.
- Monitor Elastic advisories for any further guidance on this issue.
Detection
- Review Kibana Console API request logs for unusual or unexpected file paths and JavaScript payloads.
- Alert on Kibana processes spawning shell or command interpreters (for example, child processes of the Kibana service).
- Monitor for outbound connections or file reads by the Kibana process that deviate from normal behavior.
- Audit exposed Kibana instances to confirm they are not reachable from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/106285 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHBA-2018:3743 | Third Party Advisory |
| https://discuss.elastic.co/t/elastic-stack-6-4-3-and-5-6-13-security-update/155594 | Vendor Advisory |
| https://www.elastic.co/community/security | Vendor Advisory |
| http://www.securityfocus.com/bid/106285 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHBA-2018:3743 | Third Party Advisory |
| https://discuss.elastic.co/t/elastic-stack-6-4-3-and-5-6-13-security-update/155594 | Vendor Advisory |
| https://www.elastic.co/community/security | Vendor Advisory |
Track CVE-2018-17246 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-17246), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.