Bitnami package
kibana
pkg:bitnami/kibana
Vulnerabilities (99)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-72681 | Med | 6.5 | >= 9.4.0, < 9.4.4 | 9.4.4 | Aug 13, 2026 | Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensiti | |
| CVE-2026-72680 | Med | 6.5 | >= 9.2.0, < 9.4.5 | 9.4.5 | Aug 13, 2026 | Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. A | |
| CVE-2026-72677 | Hig | 7.3 | >= 8.0.0, < 8.19.17 | 8.19.17 | Aug 13, 2026 | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The | |
| CVE-2026-72675 | Hig | 7.1 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-req | |
| CVE-2026-72674 | Med | 6.5 | >= 9.3.0, < 9.3.8 | 9.3.8 | Aug 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated | |
| CVE-2026-72673 | Med | 5.4 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it f | |
| CVE-2026-72672 | Hig | 7.7 | >= 9.1.0, < 9.4.5 | 9.4.5 | Aug 13, 2026 | The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are veri | |
| CVE-2026-72671 | Med | 4.3 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create ano | |
| CVE-2026-72670 | Hig | 7.7 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials a | |
| CVE-2026-72669 | Hig | 7.6 | >= 8.9.0, < 8.19.19 | 8.19.19 | Aug 13, 2026 | The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover th | |
| CVE-2026-72667 | Med | 6.5 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capability of the Observability lo | |
| CVE-2026-72666 | Med | 6.8 | >= 9.1.0, < 9.4.5 | 9.4.5 | Aug 13, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A | |
| CVE-2026-72665 | Hig | 8.1 | >= 8.5.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security d | |
| CVE-2026-72664 | Med | 6.5 | >= 8.9.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elasti | |
| CVE-2026-72663 | Med | 6.5 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately w | |
| CVE-2026-72661 | Med | 6.5 | >= 8.12.0, < 8.19.19 | 8.19.19 | Aug 13, 2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution | |
| CVE-2026-72660 | Med | 6.5 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying | |
| CVE-2026-72659 | Med | 6.5 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged acc | |
| CVE-2026-72658 | Hig | 7.3 | >= 8.19.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticate | |
| CVE-2026-72655 | Med | 4.3 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges |
- affected >= 9.4.0, < 9.4.4fixed 9.4.4
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensiti
- affected >= 9.2.0, < 9.4.5fixed 9.4.5
Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. A
- affected >= 8.0.0, < 8.19.17fixed 8.19.17
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-req
- affected >= 9.3.0, < 9.3.8fixed 9.3.8
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it f
- affected >= 9.1.0, < 9.4.5fixed 9.4.5
The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are veri
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create ano
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials a
- affected >= 8.9.0, < 8.19.19fixed 8.19.19
The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover th
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capability of the Observability lo
- affected >= 9.1.0, < 9.4.5fixed 9.4.5
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A
- affected >= 8.5.0, < 8.19.20fixed 8.19.20
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security d
- affected >= 8.9.0, < 8.19.20fixed 8.19.20
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elasti
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately w
- affected >= 8.12.0, < 8.19.19fixed 8.19.19
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged acc
- affected >= 8.19.0, < 8.19.20fixed 8.19.20
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticate
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges
Page 1 of 5