Elastic

Kibana

101 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 13.01.2026 21:03:13
  • Zuletzt bearbeitet 22.01.2026 19:58:42

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously cons...

  • EPSS 0.05%
  • Veröffentlicht 13.01.2026 21:02:18
  • Zuletzt bearbeitet 22.01.2026 19:57:29

Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookee...

  • EPSS 0.03%
  • Veröffentlicht 18.12.2025 22:32:17
  • Zuletzt bearbeitet 23.12.2025 19:08:18

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read...

  • EPSS 0.04%
  • Veröffentlicht 18.12.2025 22:21:09
  • Zuletzt bearbeitet 23.12.2025 19:07:36

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone...

  • EPSS 0.27%
  • Veröffentlicht 18.12.2025 22:14:51
  • Zuletzt bearbeitet 23.12.2025 19:07:51

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted ...

  • EPSS 0.11%
  • Veröffentlicht 18.12.2025 22:11:39
  • Zuletzt bearbeitet 23.12.2025 19:07:16

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via ...

  • EPSS 0.04%
  • Veröffentlicht 18.12.2025 22:08:37
  • Zuletzt bearbeitet 23.12.2025 19:07:09

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a ...

  • EPSS 0.04%
  • Veröffentlicht 15.12.2025 10:21:07
  • Zuletzt bearbeitet 18.12.2025 01:45:36

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025...

  • EPSS 0.03%
  • Veröffentlicht 12.11.2025 09:57:22
  • Zuletzt bearbeitet 11.12.2025 21:09:00

Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

  • EPSS 0.02%
  • Veröffentlicht 06.11.2025 14:27:26
  • Zuletzt bearbeitet 06.11.2025 19:45:09

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.