elastic / kibana
76 known vulnerabilities in elastic kibana.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-63137 | Medium | 0.4% | 8.3 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via… | |
| CVE-2026-72670 | Medium | 0.3% | 7.7 | A lower privileged user who holds only the privilege to read agent policies can … | |
| CVE-2026-56147 | Medium | 0.3% | 7.1 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-72629 | Medium | 0.3% | 7.1 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-4498 | Medium | 0.3% | 7.7 | Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug r… | |
| CVE-2026-33461 | Medium | 0.3% | 7.7 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure v… | |
| CVE-2026-72677 | Medium | 0.3% | 7.3 | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion… | |
| CVE-2026-78590 | Medium | 0.3% | 7.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-72672 | Medium | 0.3% | 7.7 | The Elastic Security capability that suggests existing field values while a user… | |
| CVE-2026-72665 | Medium | 0.3% | 8.1 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of … | |
| CVE-2026-72643 | Medium | 0.3% | 7.1 | Kibana Agent Builder determines whether a caller owns a private agent by compari… | |
| CVE-2026-72632 | Medium | 0.3% | 7.1 | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclos… | |
| CVE-2026-78592 | Medium | 0.3% | 7.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-72669 | Medium | 0.2% | 7.6 | The state that Kibana stores for an Observability Onboarding flow is not bound t… | |
| CVE-2026-72675 | Medium | 0.2% | 7.1 | Missing Authorization (CWE-862) in Kibana can lead to cross-space information di… | |
| CVE-2026-72630 | Medium | 0.2% | 7.1 | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalati… | |
| CVE-2026-78583 | Medium | 0.2% | 8.1 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via… | |
| CVE-2026-72658 | Medium | 0.1% | 7.3 | Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation … | |
| CVE-2026-63139 | Low | 0.5% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-63260 | Low | 0.5% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-63261 | Low | 0.5% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-42397 | Low | 0.4% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72676 | Low | 0.4% | 6.5 | Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Serv… | |
| CVE-2026-72654 | Low | 0.4% | 6.5 | Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning f… | |
| CVE-2026-72660 | Low | 0.4% | 6.5 | Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20),… | |
| CVE-2026-63138 | Low | 0.3% | 6.5 | Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kib… | |
| CVE-2026-63143 | Low | 0.3% | 4.3 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information d… | |
| CVE-2026-49089 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-78599 | Low | 0.3% | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-72681 | Low | 0.3% | 6.5 | Kibana Agent Builder does not correctly verify that the requesting user holds th… | |
| CVE-2026-33465 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72628 | Low | 0.3% | 6.5 | Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a de… | |
| CVE-2026-72644 | Low | 0.3% | 6.5 | Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input… | |
| CVE-2026-72651 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72652 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72653 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72659 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72663 | Low | 0.3% | 6.5 | Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of ser… | |
| CVE-2026-72667 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72674 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72682 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-78586 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-63142 | Low | 0.3% | 5.0 | Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authentica… | |
| CVE-2026-63259 | Low | 0.3% | 4.3 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-72664 | Low | 0.3% | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of … | |
| CVE-2026-72666 | Low | 0.3% | 6.8 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-49092 | Low | 0.3% | 4.3 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lea… | |
| CVE-2026-63262 | Low | 0.3% | 4.3 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space i… | |
| CVE-2026-72661 | Low | 0.3% | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via… | |
| CVE-2026-49094 | Low | 0.3% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… |
Page 1 of 2
Next →