← Vulnerability feed

Vulnerability record · CVE-2026-33466 · published 8 April 2026

CVE-2026-33466: Elastic logstash path traversal vulnerability

Elastic · Logstash

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed archives. An attacker who can serve a specially crafted archive to Logstash through a compromised or attacker-controlled update endpoint can write arbitrary files to the host filesystem with the privileges of the Logstash process. In certain configurations where automatic pipeline reloading is enabled, this can be escalated to remote code execution.

9.8 CVSS 3.1 Critical EPSS 0.85% · top 43.6% CWE-22 · Path traversal
9.8CVSS 3.1 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
24 Jul 2026Last modified by NVD

Description

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal (CAPEC-139). The archive extraction utilities used by Logstash do not properly validate file paths within compressed archives. An attacker who can serve a specially crafted archive to Logstash through a compromised or attacker-controlled update endpoint can write arbitrary files to the host filesystem with the privileges of the Logstash process. In certain configurations where automatic pipeline reloading is enabled, this can be escalated to remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33466 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-7612Elastic logstash error message information leak vulnerabilityA sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified …EPSS 2.4%7.5CVE-2019-7620Elastic logstash uncontrolled resource consumption vulnerabilityLogstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to …EPSS 2.1%7.5CVE-2015-5378Elastic logstash information exposure vulnerabilityLogstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash serve…EPSS 2.5%7.5CVE-2016-1000221Elastic logstash information exposure vulnerabilityLogstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.EPSS 1.8%7.5CVE-2016-1000222Elastic logstash argument injection vulnerabilityLogstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.EPSS 1.1%7.5CVE-2016-10363Elastic logstash improper resource shutdown vulnerabilityLogstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets c…EPSS 1.5%7.5CVE-2014-4326Elastic logstash os command injection vulnerabilityElasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb o…EPSS 3.3%6.5CVE-2018-3817Elastic logstash sensitive information in log file vulnerabilityWhen logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2026-33466), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.