Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Pendiente de análisis | Media (6.5) | 0.18% | — | Elastic KibanaAI | 26/9/2026 | 28/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into… | |
| Pendiente de análisis | Alta (7.3) | 0.18% | — | Elastic KibanaAI | 26/9/2026 | 29/9/2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent.… | |
| Pendiente de análisis | Media (6.3) | 0.17% | — | Elastic KibanaAI | 26/9/2026 | 28/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a Kibana space could enumerate, read,… | |
| Pendiente de análisis | Alta (8.1) | 0.39% | — | Elastic KibanaAI | 3/9/2026 | 8/9/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | Elastic KibanaAI | 3/9/2026 | 8/9/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | Elastic KibanaAI | 3/9/2026 | 8/9/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Elastic KibanaAI | 3/9/2026 | 8/9/2026 | Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | Elastic KibanaAI | 3/9/2026 | 8/9/2026 | Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Elastic KibanaAICriblAIElasticsearchAI | 3/9/2026 | 8/9/2026 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized… | |
| Analizada | Alta (8.1) | 0.39% | — | Elastic Kibana | 3/9/2026 | 8/9/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management… | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | Elastic KibanaAI | 2/9/2026 | 3/9/2026 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster… | |
| Analizada | Media (5.5) | 0.35% | — | Elastic Kibana | 2/9/2026 | 3/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from… | |
| Analizada | Media (6.5) | 0.48% | — | Elastic Kibana | 2/9/2026 | 3/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act… | |
| Analizada | Media (5.4) | 0.24% | — | Elastic Kibana | 2/9/2026 | 3/9/2026 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved… | |
| Analizada | Media (6.3) | 0.36% | — | Elastic Kibana | 2/9/2026 | 3/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration… | |
| Analizada | Alta (7.3) | 0.40% | — | Elastic Kibana | 2/9/2026 | 3/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to… | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 2/9/2026 | 3/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable… | |
| Analizada | Media (4.3) | 0.31% | — | Elastic Kibana | 2/9/2026 | 3/9/2026 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to… | |
| Analizada | Media (6.5) | 0.38% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any authenticated Kibana user to read APM server credentials that should be restricted to users holding APM or… | |
| Analizada | Media (4.2) | 0.23% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read,… | |
| Analizada | Media (4.3) | 0.29% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the… | |
| Analizada | Media (4.3) | 0.29% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and… | |
| Analizada | Alta (7.3) | 0.40% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of… |