CVE-2026-78598
- EPSS 0.14%
- Veröffentlicht 02.09.2026 14:43:15
- Zuletzt bearbeitet 03.09.2026 13:42:26
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job managemen...
CVE-2026-78601
- EPSS 0.19%
- Veröffentlicht 02.09.2026 14:43:07
- Zuletzt bearbeitet 03.09.2026 13:42:45
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kiba...
CVE-2026-63138
- EPSS 0.31%
- Veröffentlicht 01.09.2026 19:20:43
- Zuletzt bearbeitet 02.09.2026 14:12:19
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially craft...
CVE-2026-78597
- EPSS 0.17%
- Veröffentlicht 01.09.2026 19:20:41
- Zuletzt bearbeitet 02.09.2026 18:50:48
Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature ...
CVE-2026-78592
- EPSS 0.25%
- Veröffentlicht 01.09.2026 19:20:39
- Zuletzt bearbeitet 02.09.2026 14:52:18
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges coul...
CVE-2026-78606
- EPSS 0.15%
- Veröffentlicht 01.09.2026 19:20:37
- Zuletzt bearbeitet 02.09.2026 14:52:59
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different ...
CVE-2026-78603
- EPSS 0.17%
- Veröffentlicht 01.09.2026 19:20:35
- Zuletzt bearbeitet 02.09.2026 14:52:43
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature ...
CVE-2026-78608
- EPSS 0.2%
- Veröffentlicht 01.09.2026 19:20:31
- Zuletzt bearbeitet 02.09.2026 14:53:24
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any authenticated Kibana user to read APM ...
CVE-2026-72654
- EPSS 0.35%
- Veröffentlicht 01.09.2026 19:20:27
- Zuletzt bearbeitet 02.09.2026 18:49:59
Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was pe...
CVE-2026-72633
- EPSS 0.19%
- Veröffentlicht 01.09.2026 19:20:25
- Zuletzt bearbeitet 04.09.2026 20:02:43
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and ...