elastic / kibana
76 known vulnerabilities in elastic kibana.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-33459 | Low | 0.3% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-63145 | Low | 0.3% | 4.3 | Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of … | |
| CVE-2026-49095 | Low | 0.3% | 6.5 | Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management f… | |
| CVE-2026-72650 | Low | 0.3% | 4.3 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-56146 | Low | 0.2% | 5.4 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modificatio… | |
| CVE-2026-72631 | Low | 0.2% | 6.5 | Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege es… | |
| CVE-2026-78591 | Low | 0.2% | 6.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-33458 | Low | 0.2% | 6.3 | Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to informa… | |
| CVE-2026-78584 | Low | 0.2% | 4.3 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead… | |
| CVE-2026-72641 | Low | 0.2% | 5.4 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modificatio… | |
| CVE-2026-72673 | Low | 0.2% | 5.4 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of… | |
| CVE-2026-78608 | Low | 0.2% | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via… | |
| CVE-2026-72655 | Low | 0.2% | 4.3 | Improperly Controlled Modification of Dynamically-Determined Object Attributes (… | |
| CVE-2026-49096 | Low | 0.2% | 4.3 | Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via I… | |
| CVE-2026-78601 | Low | 0.2% | 5.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via… | |
| CVE-2026-49093 | Low | 0.2% | 6.3 | Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user … | |
| CVE-2026-72671 | Low | 0.2% | 4.3 | A Kibana Machine Learning capability that removes a saved object from the curren… | |
| CVE-2026-72680 | Low | 0.2% | 6.5 | Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a store… | |
| CVE-2026-72633 | Low | 0.2% | 4.3 | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss … | |
| CVE-2026-63141 | Low | 0.2% | 6.3 | Missing Authorization (CWE-862) in Kibana allows an authenticated user to access… | |
| CVE-2026-33460 | Low | 0.2% | 4.3 | Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information … | |
| CVE-2026-78597 | Low | 0.2% | 4.3 | Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to u… | |
| CVE-2026-78603 | Low | 0.2% | 4.3 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via… | |
| CVE-2026-78606 | Low | 0.2% | 4.2 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure,… | |
| CVE-2026-78598 | Low | 0.1% | 5.4 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lea… | |
| CVE-2026-78581 | Low | 0.1% | 4.2 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… |
← Prev Page 2 of 2