External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 14 Jan 2026 10:30:00 +0000

Type Values Removed Values Added
Description External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.
Title External Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Gemini Connector
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-01-14T10:14:57.415Z

Reserved: 2025-12-19T16:02:39.148Z

Link: CVE-2026-0532

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-14T11:15:50.510

Modified: 2026-01-14T11:15:50.510

Link: CVE-2026-0532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses