CVE-2026-72660
- EPSS 0.36%
- Veröffentlicht 13.08.2026 19:12:56
- Zuletzt bearbeitet 02.09.2026 14:12:58
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error con...
CVE-2026-72659
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:12:52
- Zuletzt bearbeitet 02.09.2026 14:20:44
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user h...
CVE-2026-72658
- EPSS 0.13%
- Veröffentlicht 13.08.2026 19:12:48
- Zuletzt bearbeitet 02.09.2026 14:18:12
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by ano...
CVE-2026-72667
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:11:36
- Zuletzt bearbeitet 02.09.2026 14:11:28
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capa...
CVE-2026-72666
- EPSS 0.28%
- Veröffentlicht 13.08.2026 19:11:34
- Zuletzt bearbeitet 02.09.2026 14:11:15
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Co...
CVE-2026-72665
- EPSS 0.27%
- Veröffentlicht 13.08.2026 19:11:32
- Zuletzt bearbeitet 02.09.2026 14:11:01
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author a...
CVE-2026-72664
- EPSS 0.26%
- Veröffentlicht 13.08.2026 19:11:30
- Zuletzt bearbeitet 02.09.2026 14:13:43
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule autho...
CVE-2026-72677
- EPSS 0.27%
- Veröffentlicht 13.08.2026 19:11:28
- Zuletzt bearbeitet 02.09.2026 14:09:48
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting rel...
CVE-2026-72676
- EPSS 0.36%
- Veröffentlicht 13.08.2026 19:11:26
- Zuletzt bearbeitet 04.09.2026 20:21:02
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restric...
CVE-2026-72675
- EPSS 0.22%
- Veröffentlicht 13.08.2026 19:11:24
- Zuletzt bearbeitet 02.09.2026 14:09:33
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permi...