Elastic

Kibana

202 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 03.09.2026 18:35:40
  • Zuletzt bearbeitet 08.09.2026 14:17:41

Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level ...

  • EPSS 0.16%
  • Veröffentlicht 03.09.2026 18:35:38
  • Zuletzt bearbeitet 08.09.2026 14:17:41

Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent p...

  • EPSS 0.17%
  • Veröffentlicht 03.09.2026 18:35:37
  • Zuletzt bearbeitet 08.09.2026 14:17:41

An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasti...

  • EPSS 0.2%
  • Veröffentlicht 03.09.2026 18:35:36
  • Zuletzt bearbeitet 08.09.2026 16:48:51

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint cred...

  • EPSS 0.2%
  • Veröffentlicht 02.09.2026 14:43:29
  • Zuletzt bearbeitet 03.09.2026 17:54:08

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learni...

  • EPSS 0.3%
  • Veröffentlicht 02.09.2026 14:43:24
  • Zuletzt bearbeitet 03.09.2026 13:43:50

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana...

  • EPSS 0.22%
  • Veröffentlicht 02.09.2026 14:43:22
  • Zuletzt bearbeitet 03.09.2026 13:41:38

Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled qu...

  • EPSS 0.23%
  • Veröffentlicht 02.09.2026 14:43:20
  • Zuletzt bearbeitet 03.09.2026 13:43:14

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent acti...

  • EPSS 0.28%
  • Veröffentlicht 02.09.2026 14:43:18
  • Zuletzt bearbeitet 03.09.2026 13:43:33

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Sett...

  • EPSS 0.31%
  • Veröffentlicht 02.09.2026 14:43:17
  • Zuletzt bearbeitet 03.09.2026 13:43:00

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write ...