VYPR

Kibana

by Elastic

npm: kibana

Source repositories

CVEs (161)

  • CVE-2019-7608MedMar 25, 2019
    risk 0.33cvss 6.1epss 0.01

    Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2026-26936MedFeb 26, 2026
    risk 0.32cvss 4.9epss 0.00

    Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492).

  • CVE-2024-23443MedJun 19, 2024
    risk 0.32cvss 4.9epss 0.02

    A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

  • CVE-2020-7016MedJul 27, 2020
    risk 0.31cvss 4.8epss 0.01

    Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

  • CVE-2026-72671MedAug 13, 2026
    risk 0.28cvss 4.3epss

    A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create…

  • CVE-2026-72650MedAug 13, 2026
    risk 0.28cvss 4.3epss

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve…

  • CVE-2026-49096MedAug 13, 2026
    risk 0.28cvss 4.3epss

    Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error…

  • CVE-2026-49092MedJul 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are…

  • CVE-2025-68422MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully…

  • CVE-2025-68386MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a…

  • CVE-2025-37734MedNov 12, 2025
    risk 0.28cvss 4.3epss 0.00

    Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

  • CVE-2025-25012MedJun 25, 2025
    risk 0.28cvss 4.3epss 0.00

    URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

  • CVE-2025-25016MedMay 1, 2025
    risk 0.28cvss 4.3epss 0.00

    Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.

  • CVE-2024-43710MedJan 23, 2025
    risk 0.28cvss 4.3epss 0.00

    A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to the nature of the underlying request, only endpoints available over https that return JSON could be accessed.…

  • CVE-2024-37279MedJun 13, 2024
    risk 0.28cvss 4.3epss 0.00

    A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.

  • CVE-2022-23709MedMar 3, 2022
    risk 0.28cvss 4.3epss 0.01

    A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a…

  • CVE-2021-37938MedNov 18, 2021
    risk 0.28cvss 4.3epss 0.01

    It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension. Thanks…

  • CVE-2020-10743MedJun 2, 2021
    risk 0.28cvss 4.3epss 0.01

    It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of…

  • CVE-2019-7621MedDec 18, 2019
    risk 0.28cvss 5.4epss 0.01

    Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that…

  • CVE-2026-33463MedMay 28, 2026
    risk 0.27cvss 5.3epss 0.00

    Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window,…

Page 7 of 9