Bitnami package
elk
pkg:bitnami/elk
Vulnerabilities (99)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56146 | Med | 5.4 | >= 9.4.0, < 9.4.3 | 9.4.3 | Jul 21, 2026 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchl | |
| CVE-2026-49092 | Med | 4.3 | >= 9.4.0, < 9.4.3 | 9.4.3 | Jul 21, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are no | |
| CVE-2026-42397 | Med | 6.5 | >= 9.3.0, < 9.3.7 | 9.3.7 | Jul 21, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value t | |
| CVE-2026-49095 | Med | 6.5 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into a configuration override mechanism th | |
| CVE-2026-49094 | Med | 6.5 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kiban | |
| CVE-2026-49093 | Med | 6.3 | >= 9.3.0, < 9.3.3 | 9.3.3 | May 28, 2026 | Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to bl | |
| CVE-2026-42400 | Med | 6.5 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization checks, causing excessive memory and CP | |
| CVE-2026-42399 | Med | 6.5 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visuali | |
| CVE-2026-42398 | Hig | 7.7 | >= 9.0.0, < 9.2.8 | 9.2.8 | May 28, 2026 | Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound request | |
| CVE-2026-42401 | Med | 4.1 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user, was | |
| CVE-2026-33464 | Med | 6.5 | < 9.3.5 | 9.3.5 | May 28, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially crafted, oversized payload to an internal Kibana API, causing the Kibana process | |
| CVE-2026-33463 | Med | 5.3 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window, enablin | |
| CVE-2026-33462 | Med | 4.6 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifier. When an administrator subsequently attempts to delete this dashboard through | |
| CVE-2026-33459 | Med | 6.5 | >= 8.0.0, < 8.19.14 | 8.19.14 | Apr 8, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values. When multiple suc | |
| CVE-2026-33458 | Med | 6.3 | >= 9.3.0, < 9.3.3 | 9.3.3 | Apr 8, 2026 | Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal | |
| CVE-2026-4498 | Hig | 7.7 | >= 8.0.0, < 8.19.14 | 8.19.14 | Apr 8, 2026 | Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (su | |
| CVE-2026-33461 | Hig | 7.7 | >= 8.0.0, < 8.19.14 | 8.19.14 | Apr 8, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges can exploit an internal API endpoint to retrieve sensitive configuration data, including private keys and authentication tokens, th | |
| CVE-2026-33460 | Med | 4.3 | >= 8.0.0, < 8.19.14 | 8.19.14 | Apr 8, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-122). A user with Fleet agent management privileges in one Kibana space can retrieve Fleet Server policy details from other spaces through an internal enrollment | |
| CVE-2026-26938 | Hig | 8.6 | >= 9.3.0, < 9.3.1 | 9.3.1 | Feb 26, 2026 | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). T | |
| CVE-2026-26937 | Med | 6.5 | >= 8.0.0, < 8.19.11 | 8.19.11 | Feb 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153) |
- affected >= 9.4.0, < 9.4.3fixed 9.4.3
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchl
- affected >= 9.4.0, < 9.4.3fixed 9.4.3
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are no
- affected >= 9.3.0, < 9.3.7fixed 9.3.7
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value t
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into a configuration override mechanism th
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kiban
- affected >= 9.3.0, < 9.3.3fixed 9.3.3
Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to bl
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization checks, causing excessive memory and CP
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visuali
- affected >= 9.0.0, < 9.2.8fixed 9.2.8
Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound request
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user, was
- affected < 9.3.5fixed 9.3.5
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially crafted, oversized payload to an internal Kibana API, causing the Kibana process
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window, enablin
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifier. When an administrator subsequently attempts to delete this dashboard through
- affected >= 8.0.0, < 8.19.14fixed 8.19.14
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values. When multiple suc
- affected >= 9.3.0, < 9.3.3fixed 9.3.3
Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal
- affected >= 8.0.0, < 8.19.14fixed 8.19.14
Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (su
- affected >= 8.0.0, < 8.19.14fixed 8.19.14
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges can exploit an internal API endpoint to retrieve sensitive configuration data, including private keys and authentication tokens, th
- affected >= 8.0.0, < 8.19.14fixed 8.19.14
Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-122). A user with Fleet agent management privileges in one Kibana space can retrieve Fleet Server policy details from other spaces through an internal enrollment
- affected >= 9.3.0, < 9.3.1fixed 9.3.1
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). T
- affected >= 8.0.0, < 8.19.11fixed 8.19.11
Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)
Page 3 of 5