elastic
115 known vulnerabilities affecting elastic products.
Products
kibana 76
elasticsearch 24
elastic_cloud_on_kubernetes 4
fleet_server 2
endpoint_security 1
filebeat 1
elastic_package_registry 1
apm_server 1
elastic_agent 1
logstash 1
maps_server 1
metricbeat 1
winlogbeat 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72671 | Low | 0.2% | 4.3 | A Kibana Machine Learning capability that removes a saved object from the curren… | |
| CVE-2026-72680 | Low | 0.2% | 6.5 | Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a store… | |
| CVE-2026-72633 | Low | 0.2% | 4.3 | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss … | |
| CVE-2026-78607 | Low | 0.2% | 5.4 | Missing Authorization (CWE-862) in the Elasticsearch custom inference service ca… | |
| CVE-2026-63141 | Low | 0.2% | 6.3 | Missing Authorization (CWE-862) in Kibana allows an authenticated user to access… | |
| CVE-2026-26931 | Low | 0.2% | 5.7 | Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_w… | |
| CVE-2026-78600 | Low | 0.2% | 3.5 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to un… | |
| CVE-2026-33460 | Low | 0.2% | 4.3 | Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information … | |
| CVE-2026-78597 | Low | 0.2% | 4.3 | Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to u… | |
| CVE-2026-78603 | Low | 0.2% | 4.3 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via… | |
| CVE-2026-78606 | Low | 0.2% | 4.2 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure,… | |
| CVE-2026-78598 | Low | 0.1% | 5.4 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lea… | |
| CVE-2026-33467 | Low | 0.1% | 5.9 | Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Re… | |
| CVE-2026-78581 | Low | 0.1% | 4.2 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-78609 | Low | 0.1% | 5.4 | Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead … |
← Prev Page 3 of 3