← elastic

elastic / kibana

76 known vulnerabilities in elastic kibana.

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-63137 Medium 0.4% 8.3 Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via…
CVE-2026-72670 Medium 0.3% 7.7 A lower privileged user who holds only the privilege to read agent policies can …
CVE-2026-56147 Medium 0.3% 7.1 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to…
CVE-2026-72629 Medium 0.3% 7.1 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to…
CVE-2026-4498 Medium 0.3% 7.7 Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug r…
CVE-2026-33461 Medium 0.3% 7.7 Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure v…
CVE-2026-72677 Medium 0.3% 7.3 Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion…
CVE-2026-78590 Medium 0.3% 7.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (…
CVE-2026-72672 Medium 0.3% 7.7 The Elastic Security capability that suggests existing field values while a user…
CVE-2026-72665 Medium 0.3% 8.1 Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of …
CVE-2026-72643 Medium 0.3% 7.1 Kibana Agent Builder determines whether a caller owns a private agent by compari…
CVE-2026-72632 Medium 0.3% 7.1 Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclos…
CVE-2026-78592 Medium 0.3% 7.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (…
CVE-2026-72669 Medium 0.2% 7.6 The state that Kibana stores for an Observability Onboarding flow is not bound t…
CVE-2026-72675 Medium 0.2% 7.1 Missing Authorization (CWE-862) in Kibana can lead to cross-space information di…
CVE-2026-72630 Medium 0.2% 7.1 Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalati…
CVE-2026-78583 Medium 0.2% 8.1 Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via…
CVE-2026-72658 Medium 0.1% 7.3 Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation …
CVE-2026-63139 Low 0.5% 6.5 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv…
CVE-2026-63260 Low 0.5% 6.5 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv…
CVE-2026-63261 Low 0.5% 6.5 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv…
CVE-2026-42397 Low 0.4% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-72676 Low 0.4% 6.5 Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Serv…
CVE-2026-72654 Low 0.4% 6.5 Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning f…
CVE-2026-72660 Low 0.4% 6.5 Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20),…
CVE-2026-63138 Low 0.3% 6.5 Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kib…
CVE-2026-63143 Low 0.3% 4.3 Missing Authorization (CWE-862) in Kibana can lead to unauthorized information d…
CVE-2026-49089 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-78599 Low 0.3% 6.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (…
CVE-2026-72681 Low 0.3% 6.5 Kibana Agent Builder does not correctly verify that the requesting user holds th…
CVE-2026-33465 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-72628 Low 0.3% 6.5 Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a de…
CVE-2026-72644 Low 0.3% 6.5 Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input…
CVE-2026-72651 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-72652 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-72653 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-72659 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-72663 Low 0.3% 6.5 Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of ser…
CVE-2026-72667 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-72674 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-72682 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-78586 Low 0.3% 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea…
CVE-2026-63142 Low 0.3% 5.0 Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authentica…
CVE-2026-63259 Low 0.3% 4.3 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to…
CVE-2026-72664 Low 0.3% 6.5 Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of …
CVE-2026-72666 Low 0.3% 6.8 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to…
CVE-2026-49092 Low 0.3% 4.3 Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lea…
CVE-2026-63262 Low 0.3% 4.3 Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space i…
CVE-2026-72661 Low 0.3% 6.5 Missing Authorization (CWE-862) in Kibana can lead to information disclosure via…
CVE-2026-49094 Low 0.3% 6.5 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv…
Page 1 of 2 Next →