Elastic Maps Server 8.19.19, 9.4.4, 9.5.1 Security Update (ESA-2026-148)

Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading to Unauthorized File Disclosure

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process.

Affected Versions:

  • 8.x: All versions from 8.19.11 up to and including 8.19.18
  • 9.x:
    • All versions from 9.3.0 up to and including 9.4.3
    • Version 9.5.0

Affected Configurations:

All configurations of Elastic Maps Server are affected.

Solutions and Mitigations:

The issue is resolved in Elastic Maps Server versions 8.19.19, 9.4.4, and 9.5.1.

For Users that Cannot Upgrade:

There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Severity: CVSSv3.1: Medium ( 5.3 ) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID: CVE-2026-78602
Problem Type: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Impact: Impact: CAPEC-126 - Path Traversal