VYPR

Bitnami package

kibana

pkg:bitnami/kibana

Vulnerabilities (113)

  • CVE-2026-94400MedSep 26, 2026
    affected >= 8.0.0, < 8.19.22fixed 8.19.22

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)

  • CVE-2026-78582MedSep 26, 2026
    affected >= 7.12.0, < 8.19.22fixed 8.19.22

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synth

  • CVE-2026-72668HigSep 26, 2026
    affected >= 9.4.0, < 9.4.7fixed 9.4.7

    Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who su

  • CVE-2026-72662MedSep 26, 2026
    affected >= 8.0.0, < 8.19.22fixed 8.19.22

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user granted the Timeline feature privilege in a K

  • CVE-2026-82302HigSep 3, 2026
    affected >= 8.0.0, < 8.19.21fixed 8.19.21

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • CVE-2026-82299MedSep 3, 2026
    affected >= 9.0.0, < 9.4.6fixed 9.4.6

    Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • CVE-2026-82298MedSep 3, 2026
    affected >= 8.0.0, < 8.19.21fixed 8.19.21

    Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • CVE-2026-78596MedSep 3, 2026
    affected >= 8.18.3, < 8.19.21fixed 8.19.21

    Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana spac

  • CVE-2026-78595MedSep 3, 2026
    affected >= 9.1.0, < 9.4.6fixed 9.4.6

    Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space

  • CVE-2026-78593MedSep 3, 2026
    affected >= 8.0.0, < 8.19.21fixed 8.19.21

    An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being

  • CVE-2026-78583HigSep 3, 2026
    affected >= 8.0.0, < 8.19.21fixed 8.19.21

    Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic A

  • CVE-2026-82293MedSep 2, 2026
    affected >= 8.0.0, < 8.19.21fixed 8.19.21

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their

  • CVE-2026-72633MedSep 1, 2026
    affected >= 9.1.0, < 9.4.6fixed 9.4.6

    Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, c

  • CVE-2026-78581MedAug 25, 2026
    affected >= 8.0.0, < 8.16.3fixed 8.16.3

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conv

  • CVE-2026-72681MedAug 13, 2026
    affected >= 9.4.0, < 9.4.4fixed 9.4.4

    Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensiti

  • CVE-2026-72680MedAug 13, 2026
    affected >= 9.2.0, < 9.4.5fixed 9.4.5

    Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. A

  • CVE-2026-72677HigAug 13, 2026
    affected >= 8.0.0, < 8.19.17fixed 8.19.17

    Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The

  • CVE-2026-72675HigAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-req

  • CVE-2026-72674MedAug 13, 2026
    affected >= 9.3.0, < 9.3.8fixed 9.3.8

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated

  • CVE-2026-72673MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it f

Page 1 of 6