Elastic

Kibana

202 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 13.08.2026 19:12:56
  • Zuletzt bearbeitet 02.09.2026 14:12:58

Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error con...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:12:52
  • Zuletzt bearbeitet 02.09.2026 14:20:44

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user h...

  • EPSS 0.13%
  • Veröffentlicht 13.08.2026 19:12:48
  • Zuletzt bearbeitet 02.09.2026 14:18:12

Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by ano...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:11:36
  • Zuletzt bearbeitet 02.09.2026 14:11:28

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capa...

  • EPSS 0.28%
  • Veröffentlicht 13.08.2026 19:11:34
  • Zuletzt bearbeitet 02.09.2026 14:11:15

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Co...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 19:11:32
  • Zuletzt bearbeitet 02.09.2026 14:11:01

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author a...

  • EPSS 0.26%
  • Veröffentlicht 13.08.2026 19:11:30
  • Zuletzt bearbeitet 02.09.2026 14:13:43

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule autho...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 19:11:28
  • Zuletzt bearbeitet 02.09.2026 14:09:48

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting rel...

  • EPSS 0.36%
  • Veröffentlicht 13.08.2026 19:11:26
  • Zuletzt bearbeitet 04.09.2026 20:21:02

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restric...

  • EPSS 0.22%
  • Veröffentlicht 13.08.2026 19:11:24
  • Zuletzt bearbeitet 02.09.2026 14:09:33

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permi...