Elastic

Kibana

202 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 06.10.2026 19:31:44
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensit...

  • EPSS 0.21%
  • Veröffentlicht 06.10.2026 19:31:41
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the Metrics Experience feature did not enforce a Kibana-level authoriz...

  • EPSS 0.35%
  • Veröffentlicht 06.10.2026 19:31:36
  • Zuletzt bearbeitet 08.10.2026 04:17:08

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or cus...

  • EPSS 0.41%
  • Veröffentlicht 26.09.2026 20:42:21
  • Zuletzt bearbeitet 29.09.2026 20:08:27

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)

  • EPSS 0.18%
  • Veröffentlicht 26.09.2026 20:42:13
  • Zuletzt bearbeitet 28.09.2026 16:31:47

Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space ...

  • EPSS 0.17%
  • Veröffentlicht 26.09.2026 20:42:11
  • Zuletzt bearbeitet 28.09.2026 16:31:47

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Tim...

  • EPSS 0.18%
  • Veröffentlicht 26.09.2026 20:42:09
  • Zuletzt bearbeitet 29.09.2026 04:17:57

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a...

  • EPSS 0.2%
  • Veröffentlicht 03.09.2026 18:35:44
  • Zuletzt bearbeitet 08.09.2026 14:17:41

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • EPSS 0.2%
  • Veröffentlicht 03.09.2026 18:35:43
  • Zuletzt bearbeitet 08.09.2026 14:17:41

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • EPSS 0.2%
  • Veröffentlicht 03.09.2026 18:35:42
  • Zuletzt bearbeitet 08.09.2026 14:17:41

Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).