Elastic

Kibana

202 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 13.08.2026 19:13:57
  • Zuletzt bearbeitet 02.09.2026 18:49:38

Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Ela...

  • EPSS 0.22%
  • Veröffentlicht 13.08.2026 19:13:53
  • Zuletzt bearbeitet 02.09.2026 18:49:46

Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was up...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:50
  • Zuletzt bearbeitet 02.09.2026 14:19:24

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 19:13:47
  • Zuletzt bearbeitet 03.09.2026 18:56:46

Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentic...

  • EPSS 0.22%
  • Veröffentlicht 13.08.2026 19:13:23
  • Zuletzt bearbeitet 04.09.2026 20:16:54

Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been g...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:19
  • Zuletzt bearbeitet 02.09.2026 14:20:28

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malfo...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:13
  • Zuletzt bearbeitet 02.09.2026 14:19:39

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, mal...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 19:13:09
  • Zuletzt bearbeitet 02.09.2026 14:19:30

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:13:03
  • Zuletzt bearbeitet 02.09.2026 14:13:28

Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost t...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2026 19:12:59
  • Zuletzt bearbeitet 02.09.2026 14:13:13

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not...