Kibana

Elastic · 186 CVEs

CVE-2026-102412
MEDIUM

Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure

Oct 6, 2026

CVE-2026-102410
MEDIUM

Missing Authorization in Kibana Leading to Information Disclosure

Oct 6, 2026

CVE-2026-102406
HIGH

Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data Interception

Oct 6, 2026

CVE-2026-94400
MEDIUM

Uncontrolled Resource Consumption in Kibana Leading to denial of service

Sep 26, 2026

CVE-2026-78582
MEDIUM

Missing Authorization in Kibana Leading to Unauthorized Deletion of Data

Sep 26, 2026

CVE-2026-72662
MEDIUM

Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deleti…

Sep 26, 2026

CVE-2026-72668
HIGH

Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation

Sep 26, 2026

CVE-2026-82302
HIGH

Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification

Sep 3, 2026

CVE-2026-82299
MEDIUM

Incorrect Authorization in Kibana Leading to Information Disclosure

Sep 3, 2026

CVE-2026-82298
MEDIUM

Incorrect Authorization in Kibana Leading to Denial of Service

Sep 3, 2026

CVE-2026-78596
MEDIUM

Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations

Sep 3, 2026

CVE-2026-78595
MEDIUM

Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure

Sep 3, 2026

CVE-2026-78593
MEDIUM

Improper Control of Generation of Code in Kibana Leading to Privilege Escalation

Sep 3, 2026

CVE-2026-78583
HIGH

Incorrect Authorization in Kibana Leading to Privilege Escalation

Sep 3, 2026

CVE-2026-82293
MEDIUM

Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption

Sep 2, 2026

CVE-2026-78586
MEDIUM

Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service

Sep 2, 2026

CVE-2026-78584
MEDIUM

Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure

Sep 2, 2026

CVE-2026-78591
MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resour…

Sep 2, 2026

CVE-2026-78590
HIGH

Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Re…

Sep 2, 2026

CVE-2026-78599
MEDIUM

Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources

Sep 2, 2026

CVE-2026-78598
MEDIUM

Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job Data

Sep 2, 2026

CVE-2026-78601
MEDIUM

Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure

Sep 2, 2026

CVE-2026-63138
MEDIUM

Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure

Sep 1, 2026

CVE-2026-78597
MEDIUM

Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation

Sep 1, 2026

CVE-2026-78592
HIGH

Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Re…

Sep 1, 2026

Showing 1 to 25 of 186 CVEs