Elastic

Kibana

202 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Veröffentlicht 02.09.2026 14:43:15
  • Zuletzt bearbeitet 03.09.2026 13:42:26

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job managemen...

  • EPSS 0.19%
  • Veröffentlicht 02.09.2026 14:43:07
  • Zuletzt bearbeitet 03.09.2026 13:42:45

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kiba...

  • EPSS 0.31%
  • Veröffentlicht 01.09.2026 19:20:43
  • Zuletzt bearbeitet 02.09.2026 14:12:19

Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially craft...

  • EPSS 0.17%
  • Veröffentlicht 01.09.2026 19:20:41
  • Zuletzt bearbeitet 02.09.2026 18:50:48

Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature ...

  • EPSS 0.25%
  • Veröffentlicht 01.09.2026 19:20:39
  • Zuletzt bearbeitet 02.09.2026 14:52:18

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges coul...

  • EPSS 0.15%
  • Veröffentlicht 01.09.2026 19:20:37
  • Zuletzt bearbeitet 02.09.2026 14:52:59

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different ...

  • EPSS 0.17%
  • Veröffentlicht 01.09.2026 19:20:35
  • Zuletzt bearbeitet 02.09.2026 14:52:43

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature ...

  • EPSS 0.2%
  • Veröffentlicht 01.09.2026 19:20:31
  • Zuletzt bearbeitet 02.09.2026 14:53:24

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any authenticated Kibana user to read APM ...

  • EPSS 0.35%
  • Veröffentlicht 01.09.2026 19:20:27
  • Zuletzt bearbeitet 02.09.2026 18:49:59

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was pe...

  • EPSS 0.19%
  • Veröffentlicht 01.09.2026 19:20:25
  • Zuletzt bearbeitet 04.09.2026 20:02:43

Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and ...