Bitnami package
kibana
pkg:bitnami/kibana
Vulnerabilities (109)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-63262 | Med | 4.3 | >= 9.4.0, < 9.4.4 | 9.4.4 | Jul 22, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control. | |
| CVE-2026-63261 | Med | 6.5 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory | |
| CVE-2026-63260 | Med | 6.5 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payl | |
| CVE-2026-63259 | Med | 4.3 | >= 9.4.0, < 9.4.4 | 9.4.4 | Jul 21, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access. | |
| CVE-2026-63145 | Med | 4.3 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machi | |
| CVE-2026-63143 | Med | 4.3 | >= 9.0.0, < 9.3.8 | 9.3.8 | Jul 21, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the do | |
| CVE-2026-63142 | Med | 5.0 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that sh | |
| CVE-2026-63141 | Med | 6.3 | >= 9.0.0, < 9.3.8 | 9.3.8 | Jul 21, 2026 | Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints. | |
| CVE-2026-63139 | Med | 6.5 | >= 8.0.0, < 8.19.19 | 8.19.19 | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially cr | |
| CVE-2026-56147 | Hig | 7.1 | >= 8.7.0, < 8.19.18 | 8.19.18 | Jul 21, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged auth | |
| CVE-2026-56146 | Med | 5.4 | >= 9.4.0, < 9.4.3 | 9.4.3 | Jul 21, 2026 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchl | |
| CVE-2026-49092 | Med | 4.3 | >= 9.4.0, < 9.4.3 | 9.4.3 | Jul 21, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are no | |
| CVE-2026-42397 | Med | 6.5 | >= 9.3.0, < 9.3.7 | 9.3.7 | Jul 21, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value t | |
| CVE-2026-49095 | Med | 6.5 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into a configuration override mechanism th | |
| CVE-2026-49094 | Med | 6.5 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kiban | |
| CVE-2026-49093 | Med | 6.3 | >= 9.3.0, < 9.3.3 | 9.3.3 | May 28, 2026 | Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to bl | |
| CVE-2026-42400 | Med | 6.5 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization checks, causing excessive memory and CP | |
| CVE-2026-42399 | Med | 6.5 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visuali | |
| CVE-2026-42398 | Hig | 7.7 | >= 9.0.0, < 9.2.8 | 9.2.8 | May 28, 2026 | Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound request | |
| CVE-2026-42401 | Med | 4.1 | >= 8.0.0, < 8.19.16 | 8.19.16 | May 28, 2026 | Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user, was |
- affected >= 9.4.0, < 9.4.4fixed 9.4.4
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payl
- affected >= 9.4.0, < 9.4.4fixed 9.4.4
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machi
- affected >= 9.0.0, < 9.3.8fixed 9.3.8
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the do
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that sh
- affected >= 9.0.0, < 9.3.8fixed 9.3.8
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.
- affected >= 8.0.0, < 8.19.19fixed 8.19.19
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially cr
- affected >= 8.7.0, < 8.19.18fixed 8.19.18
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged auth
- affected >= 9.4.0, < 9.4.3fixed 9.4.3
Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on watchl
- affected >= 9.4.0, < 9.4.3fixed 9.4.3
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are no
- affected >= 9.3.0, < 9.3.7fixed 9.3.7
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value t
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into a configuration override mechanism th
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kiban
- affected >= 9.3.0, < 9.3.3fixed 9.3.3
Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress controls were intended to bl
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization checks, causing excessive memory and CP
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visuali
- affected >= 9.0.0, < 9.2.8fixed 9.2.8
Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound request
- affected >= 8.0.0, < 8.19.16fixed 8.19.16
Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which, when subsequently rendered through an affected Kibana view by another user, was
Page 3 of 6