Elastic

Kibana

163 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 13.08.2026 19:11:24
  • Zuletzt bearbeitet 13.08.2026 21:18:12

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permi...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:11:22
  • Zuletzt bearbeitet 13.08.2026 21:18:11

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bound...

  • EPSS 0.21%
  • Veröffentlicht 13.08.2026 19:11:19
  • Zuletzt bearbeitet 13.08.2026 21:18:11

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space,...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 19:11:17
  • Zuletzt bearbeitet 13.08.2026 21:18:11

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kiba...

  • EPSS 0.19%
  • Veröffentlicht 13.08.2026 19:11:15
  • Zuletzt bearbeitet 13.08.2026 21:18:11

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A use...

  • EPSS 0.3%
  • Veröffentlicht 13.08.2026 19:11:13
  • Zuletzt bearbeitet 13.08.2026 21:18:11

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains prox...

  • EPSS 0.22%
  • Veröffentlicht 13.08.2026 19:11:11
  • Zuletzt bearbeitet 13.08.2026 21:18:11

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the s...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 19:11:09
  • Zuletzt bearbeitet 14.08.2026 05:17:00

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could...

  • EPSS 0.21%
  • Veröffentlicht 13.08.2026 19:11:06
  • Zuletzt bearbeitet 13.08.2026 21:18:31

Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists ...

  • EPSS 0.33%
  • Veröffentlicht 13.08.2026 19:08:07
  • Zuletzt bearbeitet 13.08.2026 21:18:07

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, a...