CVE-2026-78596
- EPSS 0.15%
- Veröffentlicht 03.09.2026 18:35:40
- Zuletzt bearbeitet 08.09.2026 14:17:41
Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level ...
CVE-2026-78595
- EPSS 0.16%
- Veröffentlicht 03.09.2026 18:35:38
- Zuletzt bearbeitet 08.09.2026 14:17:41
Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent p...
CVE-2026-78593
- EPSS 0.17%
- Veröffentlicht 03.09.2026 18:35:37
- Zuletzt bearbeitet 08.09.2026 14:17:41
An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasti...
CVE-2026-78583
- EPSS 0.2%
- Veröffentlicht 03.09.2026 18:35:36
- Zuletzt bearbeitet 08.09.2026 16:48:51
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint cred...
CVE-2026-82293
- EPSS 0.2%
- Veröffentlicht 02.09.2026 14:43:29
- Zuletzt bearbeitet 03.09.2026 17:54:08
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learni...
CVE-2026-78586
- EPSS 0.3%
- Veröffentlicht 02.09.2026 14:43:24
- Zuletzt bearbeitet 03.09.2026 13:43:50
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana...
CVE-2026-78584
- EPSS 0.22%
- Veröffentlicht 02.09.2026 14:43:22
- Zuletzt bearbeitet 03.09.2026 13:41:38
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled qu...
CVE-2026-78591
- EPSS 0.23%
- Veröffentlicht 02.09.2026 14:43:20
- Zuletzt bearbeitet 03.09.2026 13:43:14
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent acti...
CVE-2026-78590
- EPSS 0.28%
- Veröffentlicht 02.09.2026 14:43:18
- Zuletzt bearbeitet 03.09.2026 13:43:33
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Sett...
CVE-2026-78599
- EPSS 0.31%
- Veröffentlicht 02.09.2026 14:43:17
- Zuletzt bearbeitet 03.09.2026 13:43:00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write ...