Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.29% | — | Elastic Kibana | 8/4/2026 | 24/7/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-122). A user with Fleet agent management privileges in one Kibana space can retrieve Fleet Server policy details from other spaces through an internal enrollment endpoint. The endpoint bypasses… | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 19/3/2026 | 17/6/2026 | Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows an authenticated user to send a specially crafted Timelion expression that overwrites internal series data properties… | |
| Analizada | Media (6.5) | 0.33% | — | Elastic Kibana | 19/3/2026 | 17/6/2026 | Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). This requires an authenticated attacker… | |
| Analizada | Alta (7.7) | 0.44% | — | Elastic Kibana | 26/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an authenticated user who… | |
| Analizada | Alta (7.5) | 0.50% | — | Elastic Kibana | 26/2/2026 | 17/6/2026 | Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153) | |
| Analizada | Alta (7.5) | 0.53% | — | Elastic Kibana | 26/2/2026 | 17/6/2026 | Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492). | |
| Analizada | Alta (7.5) | 0.50% | — | Elastic Kibana | 26/2/2026 | 17/6/2026 | Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153) | |
| Analizada | Media (6.5) | 0.49% | — | Elastic Kibana | 26/2/2026 | 17/6/2026 | Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-only privileges to cause a Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted, malformed payload causing excessive resource consumption and resulting in… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/1/2026 | 17/6/2026 | Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector actions. The… | |
| Analizada | Media (6.5) | 0.48% | — | Elastic Kibana | 13/1/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policies. The crafted… | |
| Analizada | Media (6.5) | 0.32% | — | Elastic Kibana | 13/1/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete… | |
| Analizada | Alta (7.5) | 0.42% | — | Elastic Kibana | 13/1/2026 | 17/6/2026 | Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation… | |
| Analizada | Media (4.3) | 0.23% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully retrieve the list of live queries. | |
| Analizada | Media (6.5) | 0.31% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted HTTP request. | |
| Analizada | Media (6.1) | 0.22% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator. | |
| Analizada | Media (4.3) | 0.19% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a HTTP request. | |
| Analizada | Media (6.1) | 0.25% | — | Elastic Kibana | 18/12/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS mitigation. | |
| Analizada | Media (5.4) | 0.18% | — | Elastic Kibana | 15/12/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection. | |
| Analizada | Media (4.3) | 0.21% | — | Elastic Kibana | 12/11/2025 | 17/6/2026 | Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant. | |
| Analizada | Media (5.4) | 0.23% | — | Elastic Kibana | 10/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS) | |
| Analizada | Media (6.1) | 0.27% | — | Elastic Kibana | 10/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS) | |
| Analizada | Media (5.4) | 0.24% | — | Elastic Kibana | 7/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload. | |
| Analizada | Media (6.5) | 0.28% | — | Elastic Kibana | 28/8/2025 | 17/6/2026 | Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces. | |
| Analizada | Media (5.4) | 0.44% | — | Elastic Kibana | 25/6/2025 | 17/6/2026 | URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL. | |
| Analizada | Alta (8.8) | 0.44% | — | Elastic Kibana | 10/6/2025 | 17/6/2026 | Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint. |