Elastic

Kibana

163 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:03
  • Zuletzt bearbeitet 13.08.2026 21:18:11

Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost t...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 19:12:59
  • Zuletzt bearbeitet 13.08.2026 21:18:10

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not...

  • EPSS 0.36%
  • Veröffentlicht 13.08.2026 19:12:56
  • Zuletzt bearbeitet 13.08.2026 21:18:10

Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error con...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:12:52
  • Zuletzt bearbeitet 13.08.2026 21:18:10

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user h...

  • EPSS 0.13%
  • Veröffentlicht 13.08.2026 19:12:48
  • Zuletzt bearbeitet 14.08.2026 05:17:00

Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by ano...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:11:36
  • Zuletzt bearbeitet 13.08.2026 21:18:11

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capa...

  • EPSS 0.28%
  • Veröffentlicht 13.08.2026 19:11:34
  • Zuletzt bearbeitet 14.08.2026 17:20:28

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Co...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 19:11:32
  • Zuletzt bearbeitet 14.08.2026 17:20:28

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author a...

  • EPSS 0.26%
  • Veröffentlicht 13.08.2026 19:11:30
  • Zuletzt bearbeitet 14.08.2026 17:20:28

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule autho...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 19:11:28
  • Zuletzt bearbeitet 13.08.2026 21:18:12

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting rel...