CVE-2026-102412
- EPSS 0.28%
- Veröffentlicht 06.10.2026 19:31:44
- Zuletzt bearbeitet 07.10.2026 13:42:52
Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated Kibana user with limited Fleet management privileges could access sensit...
CVE-2026-102410
- EPSS 0.21%
- Veröffentlicht 06.10.2026 19:31:41
- Zuletzt bearbeitet 07.10.2026 13:42:52
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the Metrics Experience feature did not enforce a Kibana-level authoriz...
CVE-2026-102406
- EPSS 0.35%
- Veröffentlicht 06.10.2026 19:31:36
- Zuletzt bearbeitet 08.10.2026 04:17:08
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or cus...
CVE-2026-94400
- EPSS 0.41%
- Veröffentlicht 26.09.2026 20:42:21
- Zuletzt bearbeitet 29.09.2026 20:08:27
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-78582
- EPSS 0.18%
- Veröffentlicht 26.09.2026 20:42:13
- Zuletzt bearbeitet 28.09.2026 16:31:47
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space ...
CVE-2026-72662
- EPSS 0.17%
- Veröffentlicht 26.09.2026 20:42:11
- Zuletzt bearbeitet 28.09.2026 16:31:47
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Tim...
CVE-2026-72668
- EPSS 0.18%
- Veröffentlicht 26.09.2026 20:42:09
- Zuletzt bearbeitet 29.09.2026 04:17:57
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a...
CVE-2026-82302
- EPSS 0.2%
- Veröffentlicht 03.09.2026 18:35:44
- Zuletzt bearbeitet 08.09.2026 14:17:41
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-82299
- EPSS 0.2%
- Veröffentlicht 03.09.2026 18:35:43
- Zuletzt bearbeitet 08.09.2026 14:17:41
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-82298
- EPSS 0.2%
- Veröffentlicht 03.09.2026 18:35:42
- Zuletzt bearbeitet 08.09.2026 14:17:41
Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).