VYPR

Kibana

by Elastic

npm: kibana

Source repositories

CVEs (194)

  • CVE-2026-26936MedFeb 26, 2026
    risk 0.32cvss 4.9epss 0.00

    Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492).

  • CVE-2024-23443MedJun 19, 2024
    risk 0.32cvss 4.9epss 0.02

    A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

  • CVE-2020-7016MedJul 27, 2020
    risk 0.31cvss 4.8epss 0.01

    Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

  • CVE-2026-78601MedSep 2, 2026
    risk 0.29cvss 5.5epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly…

  • CVE-2026-82298MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

  • CVE-2026-78596MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana…

  • CVE-2026-78595MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space…

  • CVE-2026-78593MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being…

  • CVE-2026-82293MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their…

  • CVE-2026-78598MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single…

  • CVE-2026-72641MedSep 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the…

  • CVE-2026-72671MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create…

  • CVE-2026-72650MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve…

  • CVE-2026-49096MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error…

  • CVE-2026-49092MedJul 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are…

  • CVE-2025-68422MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP request. This allows an attacker who lacks the live queries - read permission to successfully…

  • CVE-2025-68386MedDec 18, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a…

  • CVE-2025-37734MedNov 12, 2025
    risk 0.28cvss 4.3epss 0.00

    Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

  • CVE-2025-25012MedJun 25, 2025
    risk 0.28cvss 4.3epss 0.00

    URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

  • CVE-2025-25016MedMay 1, 2025
    risk 0.28cvss 4.3epss 0.00

    Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.

Page 8 of 10