CVE-2026-72631
- EPSS 0.21%
- Veröffentlicht 13.08.2026 19:13:57
- Zuletzt bearbeitet 02.09.2026 18:49:38
Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Ela...
CVE-2026-72630
- EPSS 0.22%
- Veröffentlicht 13.08.2026 19:13:53
- Zuletzt bearbeitet 02.09.2026 18:49:46
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was up...
CVE-2026-72629
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:50
- Zuletzt bearbeitet 02.09.2026 14:19:24
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model...
CVE-2026-72643
- EPSS 0.25%
- Veröffentlicht 13.08.2026 19:13:47
- Zuletzt bearbeitet 03.09.2026 18:56:46
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentic...
CVE-2026-72655
- EPSS 0.22%
- Veröffentlicht 13.08.2026 19:13:23
- Zuletzt bearbeitet 04.09.2026 20:16:54
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been g...
CVE-2026-72653
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:19
- Zuletzt bearbeitet 02.09.2026 14:20:28
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malfo...
CVE-2026-72651
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:13
- Zuletzt bearbeitet 02.09.2026 14:19:39
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, mal...
CVE-2026-72650
- EPSS 0.27%
- Veröffentlicht 13.08.2026 19:13:09
- Zuletzt bearbeitet 02.09.2026 14:19:30
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single...
CVE-2026-72663
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:13:03
- Zuletzt bearbeitet 02.09.2026 14:13:28
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost t...
CVE-2026-72661
- EPSS 0.25%
- Veröffentlicht 13.08.2026 19:12:59
- Zuletzt bearbeitet 02.09.2026 14:13:13
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not...