Elastic

Kibana

163 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 08.04.2026 16:41:27
  • Zuletzt bearbeitet 24.07.2026 23:10:00

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges can exploit an internal API endpoint to retrieve sensitive configuration data, including private keys...

  • EPSS 0.3%
  • Veröffentlicht 08.04.2026 16:38:59
  • Zuletzt bearbeitet 25.07.2026 10:10:00

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fl...

  • EPSS 0.27%
  • Veröffentlicht 19.03.2026 17:14:31
  • Zuletzt bearbeitet 23.03.2026 13:35:49

Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows an authenticated user to send a specially crafted T...

  • EPSS 0.19%
  • Veröffentlicht 19.03.2026 17:11:16
  • Zuletzt bearbeitet 23.03.2026 13:36:57

Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not P...

  • EPSS 0.25%
  • Veröffentlicht 26.02.2026 17:56:48
  • Zuletzt bearbeitet 02.03.2026 15:40:36

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via...

  • EPSS 0.27%
  • Veröffentlicht 26.02.2026 17:51:35
  • Zuletzt bearbeitet 02.03.2026 15:43:52

Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)

  • EPSS 0.33%
  • Veröffentlicht 26.02.2026 17:07:40
  • Zuletzt bearbeitet 02.03.2026 16:01:07

Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492).

  • EPSS 0.28%
  • Veröffentlicht 26.02.2026 17:05:16
  • Zuletzt bearbeitet 02.03.2026 15:58:14

Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)

  • EPSS 0.28%
  • Veröffentlicht 26.02.2026 17:03:17
  • Zuletzt bearbeitet 02.03.2026 15:59:55

Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-only privileges to cause a Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted, malf...

  • EPSS 0.43%
  • Veröffentlicht 14.01.2026 10:14:57
  • Zuletzt bearbeitet 15.07.2026 02:17:54

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configurat...