Elastic

Kibana

163 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 13.08.2026 19:14:05
  • Zuletzt bearbeitet 13.08.2026 21:18:07

Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the...

  • EPSS 0.23%
  • Veröffentlicht 13.08.2026 19:14:00
  • Zuletzt bearbeitet 13.08.2026 21:18:09

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that ca...

  • EPSS 0.21%
  • Veröffentlicht 13.08.2026 19:13:57
  • Zuletzt bearbeitet 14.08.2026 05:16:59

Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Ela...

  • EPSS 0.22%
  • Veröffentlicht 13.08.2026 19:13:53
  • Zuletzt bearbeitet 14.08.2026 05:16:59

Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was up...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:50
  • Zuletzt bearbeitet 13.08.2026 21:18:08

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 19:13:47
  • Zuletzt bearbeitet 13.08.2026 21:18:09

Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentic...

  • EPSS 0.22%
  • Veröffentlicht 13.08.2026 19:13:23
  • Zuletzt bearbeitet 13.08.2026 21:18:10

Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been g...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:19
  • Zuletzt bearbeitet 13.08.2026 21:18:10

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malfo...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:13
  • Zuletzt bearbeitet 13.08.2026 21:18:10

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, mal...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 19:13:09
  • Zuletzt bearbeitet 13.08.2026 21:18:10

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single...