VYPR
Medium severity6.5NVD Advisory· Published Jun 16, 2017· Updated May 13, 2026

CVE-2016-10364

CVE-2016-10364

Description

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.

Affected products

1
  • Elastic/Elastic X-Pack Securityv5
    Range: before 5.0.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.