CVE-2026-72663
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:03
- Zuletzt bearbeitet 13.08.2026 21:18:11
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost t...
CVE-2026-72661
- EPSS 0.25%
- Veröffentlicht 13.08.2026 19:12:59
- Zuletzt bearbeitet 13.08.2026 21:18:10
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not...
CVE-2026-72660
- EPSS 0.36%
- Veröffentlicht 13.08.2026 19:12:56
- Zuletzt bearbeitet 13.08.2026 21:18:10
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error con...
CVE-2026-72659
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:12:52
- Zuletzt bearbeitet 13.08.2026 21:18:10
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user h...
CVE-2026-72658
- EPSS 0.13%
- Veröffentlicht 13.08.2026 19:12:48
- Zuletzt bearbeitet 14.08.2026 05:17:00
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by ano...
CVE-2026-72667
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:11:36
- Zuletzt bearbeitet 13.08.2026 21:18:11
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capa...
CVE-2026-72666
- EPSS 0.28%
- Veröffentlicht 13.08.2026 19:11:34
- Zuletzt bearbeitet 14.08.2026 17:20:28
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Co...
CVE-2026-72665
- EPSS 0.27%
- Veröffentlicht 13.08.2026 19:11:32
- Zuletzt bearbeitet 14.08.2026 17:20:28
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author a...
CVE-2026-72664
- EPSS 0.26%
- Veröffentlicht 13.08.2026 19:11:30
- Zuletzt bearbeitet 14.08.2026 17:20:28
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule autho...
CVE-2026-72677
- EPSS 0.27%
- Veröffentlicht 13.08.2026 19:11:28
- Zuletzt bearbeitet 13.08.2026 21:18:12
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting rel...