Kibana
Elastic · 186 CVEs
Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure
Oct 6, 2026
Missing Authorization in Kibana Leading to Information Disclosure
Oct 6, 2026
Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data Interception
Oct 6, 2026
Uncontrolled Resource Consumption in Kibana Leading to denial of service
Sep 26, 2026
Missing Authorization in Kibana Leading to Unauthorized Deletion of Data
Sep 26, 2026
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deleti…
Sep 26, 2026
Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation
Sep 26, 2026
Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification
Sep 3, 2026
Incorrect Authorization in Kibana Leading to Information Disclosure
Sep 3, 2026
Incorrect Authorization in Kibana Leading to Denial of Service
Sep 3, 2026
Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations
Sep 3, 2026
Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure
Sep 3, 2026
Improper Control of Generation of Code in Kibana Leading to Privilege Escalation
Sep 3, 2026
Incorrect Authorization in Kibana Leading to Privilege Escalation
Sep 3, 2026
Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption
Sep 2, 2026
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Sep 2, 2026
Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
Sep 2, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resour…
Sep 2, 2026
Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Re…
Sep 2, 2026
Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources
Sep 2, 2026
Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job Data
Sep 2, 2026
Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure
Sep 2, 2026
Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure
Sep 1, 2026
Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation
Sep 1, 2026
Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Re…
Sep 1, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-102412 | Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure | MEDIUM | 0.28% | Oct 6, 2026 |
| CVE-2026-102410 | Missing Authorization in Kibana Leading to Information Disclosure | MEDIUM | 0.21% | Oct 6, 2026 |
| CVE-2026-102406 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data Interception | HIGH | 0.35% | Oct 6, 2026 |
| CVE-2026-94400 | Uncontrolled Resource Consumption in Kibana Leading to denial of service | MEDIUM | 0.42% | Sep 26, 2026 |
| CVE-2026-78582 | Missing Authorization in Kibana Leading to Unauthorized Deletion of Data | MEDIUM | 0.18% | Sep 26, 2026 |
| CVE-2026-72662 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data | MEDIUM | 0.17% | Sep 26, 2026 |
| CVE-2026-72668 | Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation | HIGH | 0.18% | Sep 26, 2026 |
| CVE-2026-82302 | Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification | HIGH | 0.39% | Sep 3, 2026 |
| CVE-2026-82299 | Incorrect Authorization in Kibana Leading to Information Disclosure | MEDIUM | 0.38% | Sep 3, 2026 |
| CVE-2026-82298 | Incorrect Authorization in Kibana Leading to Denial of Service | MEDIUM | 0.37% | Sep 3, 2026 |
| CVE-2026-78596 | Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations | MEDIUM | 0.27% | Sep 3, 2026 |
| CVE-2026-78595 | Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure | MEDIUM | 0.28% | Sep 3, 2026 |
| CVE-2026-78593 | Improper Control of Generation of Code in Kibana Leading to Privilege Escalation | MEDIUM | 0.29% | Sep 3, 2026 |
| CVE-2026-78583 | Incorrect Authorization in Kibana Leading to Privilege Escalation | HIGH | 0.39% | Sep 3, 2026 |
| CVE-2026-82293 | Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption | MEDIUM | 0.37% | Sep 2, 2026 |
| CVE-2026-78586 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service | MEDIUM | 0.47% | Sep 2, 2026 |
| CVE-2026-78584 | Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure | MEDIUM | 0.31% | Sep 2, 2026 |
| CVE-2026-78591 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource Deletion | MEDIUM | 0.36% | Sep 2, 2026 |
| CVE-2026-78590 | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources | HIGH | 0.40% | Sep 2, 2026 |
| CVE-2026-78599 | Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources | MEDIUM | 0.48% | Sep 2, 2026 |
| CVE-2026-78598 | Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job Data | MEDIUM | 0.24% | Sep 2, 2026 |
| CVE-2026-78601 | Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure | MEDIUM | 0.35% | Sep 2, 2026 |
| CVE-2026-63138 | Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure | MEDIUM | 0.46% | Sep 1, 2026 |
| CVE-2026-78597 | Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation | MEDIUM | 0.29% | Sep 1, 2026 |
| CVE-2026-78592 | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources | HIGH | 0.40% | Sep 1, 2026 |
Showing 1 to 25 of 186 CVEs