VYPR

Bitnami package

kibana

pkg:bitnami/kibana

Vulnerabilities (109)

  • CVE-2026-72667MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capability of the Observability lo

  • CVE-2026-72666MedAug 13, 2026
    affected >= 9.1.0, < 9.4.5fixed 9.4.5

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A

  • CVE-2026-72665HigAug 13, 2026
    affected >= 8.5.0, < 8.19.20fixed 8.19.20

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security d

  • CVE-2026-72664MedAug 13, 2026
    affected >= 8.9.0, < 8.19.20fixed 8.19.20

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elasti

  • CVE-2026-72663MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately w

  • CVE-2026-72661MedAug 13, 2026
    affected >= 8.12.0, < 8.19.19fixed 8.19.19

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution

  • CVE-2026-72660MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying

  • CVE-2026-72659MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged acc

  • CVE-2026-72658HigAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticate

  • CVE-2026-72655MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges

  • CVE-2026-72653MedAug 13, 2026
    affected >= 8.12.0, < 8.19.19fixed 8.19.19

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the K

  • CVE-2026-72651MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the

  • CVE-2026-72650MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve a

  • CVE-2026-72643HigAug 13, 2026
    affected >= 9.4.0, < 9.4.5fixed 9.4.5

    Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct

  • CVE-2026-72632HigAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-suppl

  • CVE-2026-72631MedAug 13, 2026
    affected >= 9.1.0, < 9.4.5fixed 9.4.5

    Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to E

  • CVE-2026-72630HigAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was ev

  • CVE-2026-72629HigAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the

  • CVE-2026-49096MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error pre

  • CVE-2026-49089MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression cau

Page 2 of 6