Elastic

Kibana

163 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 21.07.2026 23:07:18
  • Zuletzt bearbeitet 03.08.2026 16:37:35

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

  • EPSS 0.27%
  • Veröffentlicht 21.07.2026 22:58:45
  • Zuletzt bearbeitet 03.08.2026 16:38:28

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the serve...

  • EPSS 0.27%
  • Veröffentlicht 21.07.2026 22:53:44
  • Zuletzt bearbeitet 03.08.2026 17:42:28

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially c...

  • EPSS 0.18%
  • Veröffentlicht 21.07.2026 22:37:09
  • Zuletzt bearbeitet 03.08.2026 17:43:23

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

  • EPSS 0.16%
  • Veröffentlicht 21.07.2026 22:31:16
  • Zuletzt bearbeitet 03.08.2026 17:49:02

Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learni...

  • EPSS 0.2%
  • Veröffentlicht 21.07.2026 22:09:42
  • Zuletzt bearbeitet 03.08.2026 17:49:47

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization re...

  • EPSS 0.17%
  • Veröffentlicht 21.07.2026 22:04:28
  • Zuletzt bearbeitet 03.08.2026 17:57:11

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests t...

  • EPSS 0.19%
  • Veröffentlicht 21.07.2026 21:08:36
  • Zuletzt bearbeitet 06.08.2026 15:45:19

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

  • EPSS 0.27%
  • Veröffentlicht 21.07.2026 20:35:06
  • Zuletzt bearbeitet 06.08.2026 12:25:00

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functiona...

  • EPSS 0.17%
  • Veröffentlicht 21.07.2026 20:17:02
  • Zuletzt bearbeitet 06.08.2026 13:02:17

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perf...