VYPR

Vendor CVEs

Elastic

All CVEs

371 total · sorted by risk
  • CVE-2026-63262MedJul 22, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

  • CVE-2026-63261MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory…

  • CVE-2026-63260MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request…

  • CVE-2026-63259MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

  • CVE-2026-63145MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a…

  • CVE-2026-63144MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within…

  • CVE-2026-63143MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the…

  • CVE-2026-63142MedJul 21, 2026
    risk 0.00cvss 5.0epss 0.00

    Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that…

  • CVE-2026-49091HigJul 1, 2026
    risk 0.00cvss 8.0epss 0.00

    Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently…

  • CVE-2026-49090MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node…

  • CVE-2026-56151MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy…

  • CVE-2026-56150MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may…

  • CVE-2026-56149MedJul 1, 2026
    risk 0.00cvss 4.9epss 0.01

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption,…

  • CVE-2026-56148MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the…

  • CVE-2026-49088MedJul 1, 2026
    risk 0.00cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may…

  • CVE-2026-49087MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk deletion request that causes excessive resource consumption, which may render…

  • CVE-2015-8131Dec 7, 2015
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2015-4152Jun 15, 2015
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary files via vectors related to dynamic field references in the path option.

  • CVE-2015-4093Jun 15, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2014-6439Oct 10, 2014
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2014-4326Jul 22, 2014
    risk 0.00cvss —epss 0.03

    Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.

Page 8 of 8