CVE-2026-42397
- EPSS 0.3%
- Veröffentlicht 21.07.2026 20:17:00
- Zuletzt bearbeitet 06.08.2026 13:10:20
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints contain...
CVE-2026-56147
- EPSS 0.25%
- Veröffentlicht 21.07.2026 20:14:59
- Zuletzt bearbeitet 06.08.2026 12:30:13
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logi...
CVE-2026-49092
- EPSS 0.17%
- Veröffentlicht 21.07.2026 19:28:36
- Zuletzt bearbeitet 06.08.2026 13:06:04
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause...
- EPSS 0.2%
- Veröffentlicht 01.07.2026 17:21:28
- Zuletzt bearbeitet 02.07.2026 18:15:39
Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the ...
CVE-2026-49088
- EPSS 0.21%
- Veröffentlicht 01.07.2026 16:59:24
- Zuletzt bearbeitet 02.07.2026 17:52:31
Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in appli...
CVE-2026-49087
- EPSS 0.28%
- Veröffentlicht 01.07.2026 16:35:19
- Zuletzt bearbeitet 02.07.2026 17:53:01
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk deletion request that causes excessive resource c...
CVE-2026-56151
- EPSS 0.28%
- Veröffentlicht 01.07.2026 16:29:25
- Zuletzt bearbeitet 02.07.2026 16:09:39
Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agen...
CVE-2026-49093
- EPSS 0.2%
- Veröffentlicht 28.05.2026 19:51:32
- Zuletzt bearbeitet 21.07.2026 10:10:00
Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egres...
CVE-2026-49094
- EPSS 0.27%
- Veröffentlicht 28.05.2026 19:49:53
- Zuletzt bearbeitet 21.07.2026 10:10:00
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collecti...
CVE-2026-49095
- EPSS 0.26%
- Veröffentlicht 28.05.2026 19:48:31
- Zuletzt bearbeitet 21.07.2026 10:10:00
Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into a confi...