Bitnami package
kibana
pkg:bitnami/kibana
Vulnerabilities (99)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-72653 | Med | 6.5 | >= 8.12.0, < 8.19.19 | 8.19.19 | Aug 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the K | |
| CVE-2026-72651 | Med | 6.5 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the | |
| CVE-2026-72650 | Med | 4.3 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve a | |
| CVE-2026-72643 | Hig | 7.1 | >= 9.4.0, < 9.4.5 | 9.4.5 | Aug 13, 2026 | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct | |
| CVE-2026-72632 | Hig | 7.1 | >= 8.19.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-suppl | |
| CVE-2026-72631 | Med | 6.5 | >= 9.1.0, < 9.4.5 | 9.4.5 | Aug 13, 2026 | Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to E | |
| CVE-2026-72630 | Hig | 7.1 | >= 8.19.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was ev | |
| CVE-2026-72629 | Hig | 7.1 | >= 8.19.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the | |
| CVE-2026-49096 | Med | 4.3 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error pre | |
| CVE-2026-49089 | Med | 6.5 | >= 8.0.0, < 8.19.20 | 8.19.20 | Aug 13, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression cau | |
| CVE-2026-63262 | Med | 4.3 | >= 9.4.0, < 9.4.4 | 9.4.4 | Jul 22, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control. | |
| CVE-2026-63261 | Med | 6.5 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory | |
| CVE-2026-63260 | Med | 6.5 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payl | |
| CVE-2026-63259 | Med | 4.3 | >= 9.4.0, < 9.4.4 | 9.4.4 | Jul 21, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access. | |
| CVE-2026-63145 | Med | 4.3 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machi | |
| CVE-2026-63143 | Med | 4.3 | >= 9.0.0, < 9.3.8 | 9.3.8 | Jul 21, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the do | |
| CVE-2026-63142 | Med | 5.0 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that sh | |
| CVE-2026-63141 | Med | 6.3 | >= 9.0.0, < 9.3.8 | 9.3.8 | Jul 21, 2026 | Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints. | |
| CVE-2026-63139 | Med | 6.5 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially cr | |
| CVE-2026-56147 | Hig | 7.1 | >= 8.7.0, < 8.19.18 | 8.19.18 | Jul 21, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged auth |
- affected >= 8.12.0, < 8.19.19fixed 8.19.19
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the K
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve a
- affected >= 9.4.0, < 9.4.5fixed 9.4.5
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct
- affected >= 8.19.0, < 8.19.20fixed 8.19.20
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-suppl
- affected >= 9.1.0, < 9.4.5fixed 9.4.5
Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to E
- affected >= 8.19.0, < 8.19.20fixed 8.19.20
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was ev
- affected >= 8.19.0, < 8.19.20fixed 8.19.20
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error pre
- affected >= 8.0.0, < 8.19.20fixed 8.19.20
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression cau
- affected >= 9.4.0, < 9.4.4fixed 9.4.4
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payl
- affected >= 9.4.0, < 9.4.4fixed 9.4.4
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machi
- affected >= 9.0.0, < 9.3.8fixed 9.3.8
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the do
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that sh
- affected >= 9.0.0, < 9.3.8fixed 9.3.8
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially cr
- affected >= 8.7.0, < 8.19.18fixed 8.19.18
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged auth
Page 2 of 5