Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33466

36
FAUCET Score

CVE-2026-33466 is a path traversal vulnerability in Logstash's archive extraction functionality that fails to properly validate file paths within compressed archives. This flaw allows attackers to write arbitrary files to the host filesystem with Logstash process privileges, and potentially achieve remote code execution if automatic pipeline reloading is enabled. The vulnerability can be exploited through a compromised or attacker-controlled update endpoint by serving a specially crafted malicious archive. The vulnerability carries a critical CVSS score of 9.8, indicating a network-exploitable flaw requiring no authentication, user interaction, or special privileges. The attack has low complexity and impacts confidentiality, integrity, and availability across the entire system. With an EPSS score of 0.004, this CVE currently has lower predicted exploitation probability compared to the average vulnerability. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. No public exploit code appears to be readily available, and community attention remains limited based on the inactive status on the Hot List. However, organizations running Logstash with automatic pipeline reloading enabled should prioritize patching due to the critical severity rating and potential for remote code execution.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 8.19.14CPE matchmatch criteria
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.2.8CPE matchmatch criteria
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:*
>= 9.3.0, < 9.3.3CPE matchmatch criteria
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:*
>= 8.0.0, <= 8.19.13CPE match
cpe:2.3:a:elastic:logstash:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 22nd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

discuss.elastic.co / t/logstash-8-19-14-9-2-8-9-3-3-security-update-esa-2026-29/385816
MitigationVendor Advisory