CVE-2026-49096
- EPSS 0.26%
- Veröffentlicht 13.08.2026 19:14:05
- Zuletzt bearbeitet 13.08.2026 21:18:07
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the...
CVE-2026-72632
- EPSS 0.23%
- Veröffentlicht 13.08.2026 19:14:00
- Zuletzt bearbeitet 13.08.2026 21:18:09
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that ca...
CVE-2026-72631
- EPSS 0.21%
- Veröffentlicht 13.08.2026 19:13:57
- Zuletzt bearbeitet 14.08.2026 05:16:59
Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Ela...
CVE-2026-72630
- EPSS 0.22%
- Veröffentlicht 13.08.2026 19:13:53
- Zuletzt bearbeitet 14.08.2026 05:16:59
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was up...
CVE-2026-72629
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:50
- Zuletzt bearbeitet 13.08.2026 21:18:08
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model...
CVE-2026-72643
- EPSS 0.25%
- Veröffentlicht 13.08.2026 19:13:47
- Zuletzt bearbeitet 13.08.2026 21:18:09
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentic...
CVE-2026-72655
- EPSS 0.22%
- Veröffentlicht 13.08.2026 19:13:23
- Zuletzt bearbeitet 13.08.2026 21:18:10
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been g...
CVE-2026-72653
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:19
- Zuletzt bearbeitet 13.08.2026 21:18:10
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malfo...
CVE-2026-72651
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:13
- Zuletzt bearbeitet 13.08.2026 21:18:10
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, mal...
CVE-2026-72650
- EPSS 0.27%
- Veröffentlicht 13.08.2026 19:13:09
- Zuletzt bearbeitet 13.08.2026 21:18:10
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single...