elastic
115 known vulnerabilities affecting elastic products.
Products
kibana 76
elasticsearch 24
elastic_cloud_on_kubernetes 4
fleet_server 2
endpoint_security 1
filebeat 1
elastic_package_registry 1
apm_server 1
elastic_agent 1
logstash 1
maps_server 1
metricbeat 1
winlogbeat 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72649 | Medium | 0.6% | 8.8 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learnin… | |
| CVE-2026-33466 | Medium | 0.5% | 8.1 | Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash… | |
| CVE-2026-63137 | Medium | 0.4% | 8.3 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via… | |
| CVE-2026-72670 | Medium | 0.3% | 7.7 | A lower privileged user who holds only the privilege to read agent policies can … | |
| CVE-2026-72642 | Medium | 0.3% | 8.8 | The native inference process that Elasticsearch uses to evaluate uploaded machin… | |
| CVE-2026-56147 | Medium | 0.3% | 7.1 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-72629 | Medium | 0.3% | 7.1 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-4498 | Medium | 0.3% | 7.7 | Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug r… | |
| CVE-2026-33461 | Medium | 0.3% | 7.7 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure v… | |
| CVE-2026-72677 | Medium | 0.3% | 7.3 | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion… | |
| CVE-2026-78590 | Medium | 0.3% | 7.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-72672 | Medium | 0.3% | 7.7 | The Elastic Security capability that suggests existing field values while a user… | |
| CVE-2026-72665 | Medium | 0.3% | 8.1 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of … | |
| CVE-2026-72643 | Medium | 0.3% | 7.1 | Kibana Agent Builder determines whether a caller owns a private agent by compari… | |
| CVE-2026-72632 | Medium | 0.3% | 7.1 | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclos… | |
| CVE-2026-78592 | Medium | 0.3% | 7.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-72669 | Medium | 0.2% | 7.6 | The state that Kibana stores for an Observability Onboarding flow is not bound t… | |
| CVE-2026-72675 | Medium | 0.2% | 7.1 | Missing Authorization (CWE-862) in Kibana can lead to cross-space information di… | |
| CVE-2026-72630 | Medium | 0.2% | 7.1 | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalati… | |
| CVE-2026-78583 | Medium | 0.2% | 8.1 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via… | |
| CVE-2026-72658 | Medium | 0.1% | 7.3 | Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation … | |
| CVE-2024-14047 | Medium | 0.1% | 7.2 | A local vulnerability in the Winlogbeat Windows installer caused runtime files t… | |
| CVE-2026-78604 | Medium | 0.1% | 7.8 | Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent… | |
| CVE-2026-63139 | Low | 0.5% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-63260 | Low | 0.5% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-63261 | Low | 0.5% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-42397 | Low | 0.4% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72676 | Low | 0.4% | 6.5 | Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Serv… | |
| CVE-2026-78602 | Low | 0.4% | 5.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-72654 | Low | 0.4% | 6.5 | Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning f… | |
| CVE-2026-72660 | Low | 0.4% | 6.5 | Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20),… | |
| CVE-2026-72683 | Low | 0.4% | 6.5 | A flaw in Elasticsearch allows an authenticated user with the privileges require… | |
| CVE-2026-72686 | Low | 0.4% | 6.5 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a s… | |
| CVE-2026-63138 | Low | 0.3% | 6.5 | Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kib… | |
| CVE-2026-63143 | Low | 0.3% | 4.3 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information d… | |
| CVE-2026-49089 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-56145 | Low | 0.3% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial … | |
| CVE-2026-72678 | Low | 0.3% | 6.5 | Elasticsearch does not validate a size value taken from a user-supplied input be… | |
| CVE-2026-72679 | Low | 0.3% | 6.5 | Elasticsearch does not apply its configurable input length restriction to a user… | |
| CVE-2026-56143 | Low | 0.3% | 4.9 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch … | |
| CVE-2026-72648 | Low | 0.3% | 6.5 | Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) … | |
| CVE-2026-78599 | Low | 0.3% | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-56152 | Low | 0.3% | 5.3 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information… | |
| CVE-2026-72636 | Low | 0.3% | 6.5 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper c… | |
| CVE-2026-72681 | Low | 0.3% | 6.5 | Kibana Agent Builder does not correctly verify that the requesting user holds th… | |
| CVE-2026-33465 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72628 | Low | 0.3% | 6.5 | Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a de… | |
| CVE-2026-72638 | Low | 0.3% | 6.5 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service … | |
| CVE-2026-72639 | Low | 0.3% | 6.5 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted … | |
| CVE-2026-72644 | Low | 0.3% | 6.5 | Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input… |
Page 1 of 3
Next →