Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.37% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery… | |
| Analizada | Alta (8.1) | 0.47% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response… | |
| Analizada | Media (6.5) | 0.40% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the input. Because the… | |
| Analizada | Media (6.5) | 0.38% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its… | |
| Analizada | Media (6.5) | 0.52% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged access is not correctly validated before… | |
| Analizada | Alta (7.3) | 0.18% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in… | |
| Analizada | Media (4.3) | 0.31% | — | Elastic Kibana | 13/8/2026 | 4/9/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges, via Manipulating User-Controlled… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive… | |
| Analizada | Media (4.3) | 0.34% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve alerting rule execution telemetry that… | |
| Analizada | Alta (7.1) | 0.38% | — | Elastic Kibana | 13/8/2026 | 3/9/2026 | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in… | |
| Analizada | Alta (7.1) | 0.35% | — | Elastic Kibana | 13/8/2026 | 3/9/2026 | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored… | |
| Analizada | Media (6.5) | 0.33% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to Elastic Agents enrolled in the… | |
| Analizada | Alta (7.1) | 0.31% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration… | |
| Analizada | Alta (7.1) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read,… | |
| Analizada | Baja (3.5) | 0.29% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being… | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana process to spend an… | |
| Analizada | Media (4.3) | 0.28% | — | Elastic Kibana | 22/7/2026 | 3/8/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control. | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users. | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payload. Processing this user-supplied… | |
| Analizada | Media (4.3) | 0.29% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access. | |
| Analizada | Media (4.3) | 0.27% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning management endpoint performs… | |
| Analizada | Media (4.3) | 0.33% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may… |