4.3
CVE-2026-82298
- EPSS 0.2%
- Veröffentlicht 03.09.2026 18:35:42
- Zuletzt bearbeitet 08.09.2026 14:17:41
- Erkennungen
Incorrect Authorization in Kibana Leading to Denial of Service
Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerElastic
≫
Produkt
Kibana
Default Statusunaffected
Version <=
8.19.20
Version
8.0.0
Status
affected
Version <=
9.4.5
Version
9.0.0
Status
affected
Version <=
9.5.2
Version
9.5.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.092 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-174/390162