« Volver al listado

Elastic

Elastic Kibana: vulnerabilidades y CVE

Elastic Kibana tiene 196 vulnerabilidades publicadas, 119 de ellas en los últimos 12 meses. 8 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE196
Últimos 12 meses119
Críticas8
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2019-7609Crítica (10)95%⚠ Explotación activa25 mar 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-94400Media (6.5)0.42%—26 sept 2026
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-78582Media (6.5)0.18%—26 sept 2026
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges…
CVE-2026-72668Alta (7.3)0.18%—26 sept 2026
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be…
CVE-2026-72662Media (6.3)0.17%—26 sept 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An…
CVE-2026-82302Alta (8.1)0.39%—3 sept 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-82299Media (6.5)0.38%—3 sept 2026
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-82298Media (4.3)0.37%—3 sept 2026
Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-78596Media (4.3)0.27%—3 sept 2026
Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated…
CVE-2026-78595Media (4.3)0.28%—3 sept 2026
Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user…
CVE-2026-78593Media (4.3)0.29%—3 sept 2026
An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script…
CVE-2026-78583Alta (8.1)0.39%—3 sept 2026
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated…
CVE-2026-82293Media (4.3)0.37%—2 sept 2026
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated…
CVE-2026-78601Media (5.5)0.35%—2 sept 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an…
CVE-2026-78599Media (6.5)0.48%—2 sept 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A…
CVE-2026-78598Media (5.4)0.24%—2 sept 2026
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding…
CVE-2026-78591Media (6.3)0.36%—2 sept 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged…
CVE-2026-78590Alta (7.3)0.40%—2 sept 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A…
CVE-2026-78586Media (6.5)0.47%—2 sept 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially…
CVE-2026-78584Media (4.3)0.31%—2 sept 2026
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could…
CVE-2026-78608Media (6.5)0.38%—1 sept 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any…
CVE-2026-78606Media (4.2)0.23%—1 sept 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated…
CVE-2026-78603Media (4.3)0.29%—1 sept 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch…
CVE-2026-78597Media (4.3)0.29%—1 sept 2026
Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only…
CVE-2026-78592Alta (7.3)0.40%—1 sept 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user…
CVE-2026-72682Media (6.5)0.42%—1 sept 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges…
CVE-2026-72654Media (6.5)0.51%—1 sept 2026
Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the…
CVE-2026-72652Media (6.5)0.42%—1 sept 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes…
CVE-2026-72644Media (6.5)0.42%—1 sept 2026
Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI…
CVE-2026-72641Media (5.4)0.31%—1 sept 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read…
CVE-2026-72633Media (4.3)0.27%—1 sept 2026
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services22
  2. T1190 Exploit Public-Facing Application8
  3. T1203 Exploitation for Client Execution7
  4. T1005 Data from Local System5
  5. T1059 Command and Scripting Interpreter4
  6. T1078 Valid Accounts4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Elastic