CVE-2026-63262
- EPSS 0.17%
- Veröffentlicht 21.07.2026 23:07:18
- Zuletzt bearbeitet 03.08.2026 16:37:35
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
CVE-2026-63261
- EPSS 0.27%
- Veröffentlicht 21.07.2026 22:58:45
- Zuletzt bearbeitet 03.08.2026 16:38:28
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the serve...
CVE-2026-63260
- EPSS 0.27%
- Veröffentlicht 21.07.2026 22:53:44
- Zuletzt bearbeitet 03.08.2026 17:42:28
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially c...
CVE-2026-63259
- EPSS 0.18%
- Veröffentlicht 21.07.2026 22:37:09
- Zuletzt bearbeitet 03.08.2026 17:43:23
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
CVE-2026-63145
- EPSS 0.16%
- Veröffentlicht 21.07.2026 22:31:16
- Zuletzt bearbeitet 03.08.2026 17:49:02
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learni...
CVE-2026-63143
- EPSS 0.2%
- Veröffentlicht 21.07.2026 22:09:42
- Zuletzt bearbeitet 03.08.2026 17:49:47
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization re...
- EPSS 0.17%
- Veröffentlicht 21.07.2026 22:04:28
- Zuletzt bearbeitet 03.08.2026 17:57:11
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests t...
CVE-2026-63141
- EPSS 0.19%
- Veröffentlicht 21.07.2026 21:08:36
- Zuletzt bearbeitet 06.08.2026 15:45:19
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.
CVE-2026-63139
- EPSS 0.27%
- Veröffentlicht 21.07.2026 20:35:06
- Zuletzt bearbeitet 06.08.2026 12:25:00
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functiona...
CVE-2026-56146
- EPSS 0.17%
- Veröffentlicht 21.07.2026 20:17:02
- Zuletzt bearbeitet 06.08.2026 13:02:17
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perf...