CVE-2026-33466 is a path traversal vulnerability in Logstash's archive extraction functionality that fails to properly validate file paths within compressed archives. This flaw allows attackers to write arbitrary files to the host filesystem with Logstash process privileges, and potentially achieve remote code execution if automatic pipeline reloading is enabled. The vulnerability can be exploited through a compromised or attacker-controlled update endpoint by serving a specially crafted malicious archive. The vulnerability carries a critical CVSS score of 9.8, indicating a network-exploitable flaw requiring no authentication, user interaction, or special privileges. The attack has low complexity and impacts confidentiality, integrity, and availability across the entire system. With an EPSS score of 0.004, this CVE currently has lower predicted exploitation probability compared to the average vulnerability. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. No public exploit code appears to be readily available, and community attention remains limited based on the inactive status on the Hot List. However, organizations running Logstash with automatic pipeline reloading enabled should prioritize patching due to the critical severity rating and potential for remote code execution.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.19.14CPE matchmatch criteria | cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.2.8CPE matchmatch criteria | cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:* | ||
>= 9.3.0, < 9.3.3CPE matchmatch criteria | cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.19.13CPE match | cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.