« Volver al listado

CVE-2026-49088

Estado: AnalizadaMedia (4.4)—

Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may be accessible to operators with log access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-49088",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-49088",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-01T17:19:40.665767Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@elastic.co",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "security@elastic.co",
      "affectedData": [
        {
          "vendor": "Elastic",
          "product": "Kibana",
          "versions": [
            {
              "status": "affected",
              "version": "8.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.18.8"
            },
            {
              "status": "affected",
              "version": "9.1.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.1.5"
            },
            {
              "status": "affected",
              "version": "9.0.0",
              "versionType": "semver",
              "lessThanOrEqual": "9.0.7"
            },
            {
              "status": "affected",
              "version": "8.19.0",
              "versionType": "semver",
              "lessThanOrEqual": "8.19.5"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-01T17:16:35.807",
  "references": [
    {
      "url": "https://discuss.elastic.co/t/kibana-8-18-9-8-19-6-9-0-8-9-1-6-security-update-esa-2026-50",
      "tags": [
        "Vendor Advisory",
        "Mitigation"
      ],
      "source": "security@elastic.co"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@elastic.co",
      "description": [
        {
          "lang": "en",
          "value": "CWE-532"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may be accessible to operators with log access."
    }
  ],
  "lastModified": "2026-07-02T17:52:31.750",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5F75DB5-0F27-44B3-9C94-8541677346E1",
              "versionEndExcluding": "8.18.9",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C99F0C5B-1E48-40FB-AF72-59D86CEC45B3",
              "versionEndExcluding": "8.19.6",
              "versionStartIncluding": "8.19.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5D3776F-14E6-48FF-9D0B-67A772CD2D98",
              "versionEndExcluding": "9.0.8",
              "versionStartIncluding": "9.0.0"
            },
            {
              "criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D738E5D-7D73-493B-A13F-BBDF4655BC88",
              "versionEndExcluding": "9.1.6",
              "versionStartIncluding": "9.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@elastic.co"
}