CVE-2026-0532
- EPSS 0.04%
- Veröffentlicht 14.01.2026 10:14:57
- Zuletzt bearbeitet 14.01.2026 16:25:12
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configurat...
CVE-2026-0543
- EPSS 0.07%
- Veröffentlicht 13.01.2026 21:15:51
- Zuletzt bearbeitet 22.01.2026 20:04:20
Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-le...
CVE-2026-0531
- EPSS 0.04%
- Veröffentlicht 13.01.2026 21:15:50
- Zuletzt bearbeitet 22.01.2026 19:59:54
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewe...
CVE-2026-0530
- EPSS 0.04%
- Veröffentlicht 13.01.2026 21:03:13
- Zuletzt bearbeitet 22.01.2026 19:58:42
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously cons...
CVE-2026-0528
- EPSS 0.05%
- Veröffentlicht 13.01.2026 21:02:18
- Zuletzt bearbeitet 22.01.2026 19:57:29
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookee...
CVE-2025-68422
- EPSS 0.03%
- Veröffentlicht 18.12.2025 22:32:17
- Zuletzt bearbeitet 23.12.2025 19:08:18
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read...
CVE-2025-68386
- EPSS 0.04%
- Veröffentlicht 18.12.2025 22:21:09
- Zuletzt bearbeitet 23.12.2025 19:07:36
Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone...
CVE-2025-68389
- EPSS 0.25%
- Veröffentlicht 18.12.2025 22:14:51
- Zuletzt bearbeitet 23.12.2025 19:07:51
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted ...
CVE-2025-68387
- EPSS 0.09%
- Veröffentlicht 18.12.2025 22:11:39
- Zuletzt bearbeitet 23.12.2025 19:07:16
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via ...
CVE-2025-68385
- EPSS 0.04%
- Veröffentlicht 18.12.2025 22:08:37
- Zuletzt bearbeitet 23.12.2025 19:07:09
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a ...