CVE-2026-72641
- EPSS 0.21%
- Veröffentlicht 01.09.2026 19:20:23
- Zuletzt bearbeitet 02.09.2026 14:21:12
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could...
CVE-2026-72628
- EPSS 0.3%
- Veröffentlicht 01.09.2026 19:20:21
- Zuletzt bearbeitet 02.09.2026 14:14:18
Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a...
CVE-2026-72644
- EPSS 0.3%
- Veröffentlicht 01.09.2026 19:20:19
- Zuletzt bearbeitet 02.09.2026 14:22:14
Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially...
CVE-2026-72682
- EPSS 0.3%
- Veröffentlicht 01.09.2026 19:20:16
- Zuletzt bearbeitet 02.09.2026 14:22:42
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafte...
CVE-2026-63137
- EPSS 0.33%
- Veröffentlicht 01.09.2026 19:20:14
- Zuletzt bearbeitet 02.09.2026 14:18:25
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run w...
CVE-2026-72652
- EPSS 0.3%
- Veröffentlicht 01.09.2026 19:20:12
- Zuletzt bearbeitet 02.09.2026 14:22:27
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, wh...
CVE-2026-33465
- EPSS 0.3%
- Veröffentlicht 01.09.2026 19:20:09
- Zuletzt bearbeitet 02.09.2026 14:10:16
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could submit a specially crafted request that causes exces...
CVE-2026-78581
- EPSS 0.13%
- Veröffentlicht 25.08.2026 13:19:31
- Zuletzt bearbeitet 02.09.2026 14:10:03
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference an...
CVE-2026-49096
- EPSS 0.26%
- Veröffentlicht 13.08.2026 19:14:05
- Zuletzt bearbeitet 02.09.2026 18:49:51
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the...
CVE-2026-72632
- EPSS 0.23%
- Veröffentlicht 13.08.2026 19:14:00
- Zuletzt bearbeitet 03.09.2026 18:38:00
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that ca...