6.5
CVE-2026-82299
- EPSS 0.2%
- Veröffentlicht 03.09.2026 18:35:43
- Zuletzt bearbeitet 08.09.2026 14:17:41
- Erkennungen
Incorrect Authorization in Kibana Leading to Information Disclosure
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerElastic
≫
Produkt
Kibana
Default Statusunaffected
Version <=
9.4.5
Version
9.0.0
Status
affected
Version <=
9.5.2
Version
9.5.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.104 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://discuss.elastic.co/t/kibana-9-4-6-9-5-3-security-update-esa-2026-175/390163