Bitnami package
kibana
pkg:bitnami/kibana
Vulnerabilities (113)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-94400 | Med | 6.5 | >= 8.0.0, < 8.19.22 | 8.19.22 | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) | |
| CVE-2026-78582 | Med | 6.5 | >= 7.12.0, < 8.19.22 | 8.19.22 | Sep 26, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synth | |
| CVE-2026-72668 | Hig | 7.3 | >= 9.4.0, < 9.4.7 | 9.4.7 | Sep 26, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who su | |
| CVE-2026-72662 | Med | 6.3 | >= 8.0.0, < 8.19.22 | 8.19.22 | Sep 26, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a K | |
| CVE-2026-82302 | Hig | 8.1 | >= 8.0.0, < 8.19.21 | 8.19.21 | Sep 3, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| CVE-2026-82299 | Med | 6.5 | >= 9.0.0, < 9.4.6 | 9.4.6 | Sep 3, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| CVE-2026-82298 | Med | 4.3 | >= 8.0.0, < 8.19.21 | 8.19.21 | Sep 3, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| CVE-2026-78596 | Med | 4.3 | >= 8.18.3, < 8.19.21 | 8.19.21 | Sep 3, 2026 | Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana spac | |
| CVE-2026-78595 | Med | 4.3 | >= 9.1.0, < 9.4.6 | 9.4.6 | Sep 3, 2026 | Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space | |
| CVE-2026-78593 | Med | 4.3 | >= 8.0.0, < 8.19.21 | 8.19.21 | Sep 3, 2026 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being | |
| CVE-2026-78583 | Hig | 8.1 | >= 8.0.0, < 8.19.21 | 8.19.21 | Sep 3, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic A | |
| CVE-2026-82293 | Med | 4.3 | >= 8.0.0, < 8.19.21 | 8.19.21 | Sep 2, 2026 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their | |
| CVE-2026-72633 | Med | 4.3 | >= 9.1.0, < 9.4.6 | 9.4.6 | Sep 1, 2026 | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, c | |
| CVE-2026-78581 | Med | 4.2 | >= 8.0.0, < 8.16.3 | 8.16.3 | Aug 25, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conv | |
| CVE-2026-72681 | Med | 6.5 | >= 9.4.0, < 9.4.4 | 9.4.4 | Aug 13, 2026 | Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensiti | |
| CVE-2026-72680 | Med | 6.5 | >= 9.2.0, < 9.4.5 | 9.4.5 | Aug 13, 2026 | Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. A | |
| CVE-2026-72677 | Hig | 7.3 | >= 8.0.0, < 8.19.17 | 8.19.17 | Aug 13, 2026 | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The | |
| CVE-2026-72675 | Hig | 7.1 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-req | |
| CVE-2026-72674 | Med | 6.5 | >= 9.3.0, < 9.3.8 | 9.3.8 | Aug 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated | |
| CVE-2026-72673 | Med | 5.4 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it f |
- affected >= 8.0.0, < 8.19.22fixed 8.19.22
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
- affected >= 7.12.0, < 8.19.22fixed 8.19.22
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synth
- affected >= 9.4.0, < 9.4.7fixed 9.4.7
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who su
- affected >= 8.0.0, < 8.19.22fixed 8.19.22
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a K
- affected >= 8.0.0, < 8.19.21fixed 8.19.21
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
- affected >= 9.0.0, < 9.4.6fixed 9.4.6
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
- affected >= 8.0.0, < 8.19.21fixed 8.19.21
Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
- affected >= 8.18.3, < 8.19.21fixed 8.19.21
Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana spac
- affected >= 9.1.0, < 9.4.6fixed 9.4.6
Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space
- affected >= 8.0.0, < 8.19.21fixed 8.19.21
An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being
- affected >= 8.0.0, < 8.19.21fixed 8.19.21
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic A
- affected >= 8.0.0, < 8.19.21fixed 8.19.21
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their
- affected >= 9.1.0, < 9.4.6fixed 9.4.6
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, c
- affected >= 8.0.0, < 8.16.3fixed 8.16.3
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conv
- affected >= 9.4.0, < 9.4.4fixed 9.4.4
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensiti
- affected >= 9.2.0, < 9.4.5fixed 9.4.5
Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. A
- affected >= 8.0.0, < 8.19.17fixed 8.19.17
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-req
- affected >= 9.3.0, < 9.3.8fixed 9.3.8
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it f
Page 1 of 6