Elastic
Elastic Kibana: vulnerabilidades y CVE
Elastic Kibana tiene 196 vulnerabilidades publicadas, 119 de ellas en los últimos 12 meses. 8 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE196
Últimos 12 meses119
Críticas8
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-7609 | Crítica (10) | 95% | ⚠ Explotación activa | 25 mar 2019 | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94400 | Media (6.5) | 0.42% | — | 26 sept 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-78582 | Media (6.5) | 0.18% | — | 26 sept 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges… |
| CVE-2026-72668 | Alta (7.3) | 0.18% | — | 26 sept 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be… |
| CVE-2026-72662 | Media (6.3) | 0.17% | — | 26 sept 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An… |
| CVE-2026-82302 | Alta (8.1) | 0.39% | — | 3 sept 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). |
| CVE-2026-82299 | Media (6.5) | 0.38% | — | 3 sept 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). |
| CVE-2026-82298 | Media (4.3) | 0.37% | — | 3 sept 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). |
| CVE-2026-78596 | Media (4.3) | 0.27% | — | 3 sept 2026 | Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated… |
| CVE-2026-78595 | Media (4.3) | 0.28% | — | 3 sept 2026 | Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user… |
| CVE-2026-78593 | Media (4.3) | 0.29% | — | 3 sept 2026 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script… |
| CVE-2026-78583 | Alta (8.1) | 0.39% | — | 3 sept 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated… |
| CVE-2026-82293 | Media (4.3) | 0.37% | — | 2 sept 2026 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated… |
| CVE-2026-78601 | Media (5.5) | 0.35% | — | 2 sept 2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an… |
| CVE-2026-78599 | Media (6.5) | 0.48% | — | 2 sept 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A… |
| CVE-2026-78598 | Media (5.4) | 0.24% | — | 2 sept 2026 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding… |
| CVE-2026-78591 | Media (6.3) | 0.36% | — | 2 sept 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged… |
| CVE-2026-78590 | Alta (7.3) | 0.40% | — | 2 sept 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A… |
| CVE-2026-78586 | Media (6.5) | 0.47% | — | 2 sept 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially… |
| CVE-2026-78584 | Media (4.3) | 0.31% | — | 2 sept 2026 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could… |
| CVE-2026-78608 | Media (6.5) | 0.38% | — | 1 sept 2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any… |
| CVE-2026-78606 | Media (4.2) | 0.23% | — | 1 sept 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated… |
| CVE-2026-78603 | Media (4.3) | 0.29% | — | 1 sept 2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch… |
| CVE-2026-78597 | Media (4.3) | 0.29% | — | 1 sept 2026 | Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only… |
| CVE-2026-78592 | Alta (7.3) | 0.40% | — | 1 sept 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user… |
| CVE-2026-72682 | Media (6.5) | 0.42% | — | 1 sept 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges… |
| CVE-2026-72654 | Media (6.5) | 0.51% | — | 1 sept 2026 | Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the… |
| CVE-2026-72652 | Media (6.5) | 0.42% | — | 1 sept 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes… |
| CVE-2026-72644 | Media (6.5) | 0.42% | — | 1 sept 2026 | Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI… |
| CVE-2026-72641 | Media (5.4) | 0.31% | — | 1 sept 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read… |
| CVE-2026-72633 | Media (4.3) | 0.27% | — | 1 sept 2026 | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.