VYPR

Bitnami package

elk

pkg:bitnami/elk

Vulnerabilities (99)

  • CVE-2026-72681MedAug 13, 2026
    affected >= 9.4.0, < 9.4.4fixed 9.4.4

    Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensiti

  • CVE-2026-72680MedAug 13, 2026
    affected >= 9.2.0, < 9.4.5fixed 9.4.5

    Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. A

  • CVE-2026-72677HigAug 13, 2026
    affected >= 8.0.0, < 8.19.17fixed 8.19.17

    Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The

  • CVE-2026-72675HigAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-req

  • CVE-2026-72674MedAug 13, 2026
    affected >= 9.3.0, < 9.3.8fixed 9.3.8

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated

  • CVE-2026-72673MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it f

  • CVE-2026-72672HigAug 13, 2026
    affected >= 9.1.0, < 9.4.5fixed 9.4.5

    The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are veri

  • CVE-2026-72671MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create ano

  • CVE-2026-72670HigAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials a

  • CVE-2026-72669HigAug 13, 2026
    affected >= 8.9.0, < 8.19.19fixed 8.19.19

    The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover th

  • CVE-2026-72667MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capability of the Observability lo

  • CVE-2026-72666MedAug 13, 2026
    affected >= 9.1.0, < 9.4.5fixed 9.4.5

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A

  • CVE-2026-72665HigAug 13, 2026
    affected >= 8.5.0, < 8.19.20fixed 8.19.20

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security d

  • CVE-2026-72664MedAug 13, 2026
    affected >= 8.9.0, < 8.19.20fixed 8.19.20

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elasti

  • CVE-2026-72663MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately w

  • CVE-2026-72661MedAug 13, 2026
    affected >= 8.12.0, < 8.19.19fixed 8.19.19

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution

  • CVE-2026-72660MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying

  • CVE-2026-72659MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged acc

  • CVE-2026-72658HigAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticate

  • CVE-2026-72655MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges

Page 1 of 5