Winlogbeat 的 Windows 安装程序存在一个本地漏洞,导致运行时文件被放置在一个非特权用户可写的目录中。具有系统现有访问权限的低权限攻击者可以预先布置恶意的文件系统链接,使得后续以较高权限运行的 Winlogbeat 操作会写入或删除任意文件。成功利用该漏洞可能导致服务中断(拒绝服务)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elastic Security | 7.6.0≤ 8.12.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elastic Security | 7.6.0 ~ 8.12.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72649 | 8.8 HIGH | Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution |
| CVE-2026-63137 | 8.3 HIGH | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-78592 | 7.3 HIGH | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori |
| CVE-2026-33465 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-63138 | 6.5 MEDIUM | Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Infor |
| CVE-2026-78608 | 6.5 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-72654 | 6.5 MEDIUM | Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure |
| CVE-2026-72628 | 6.5 MEDIUM | Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service |
| CVE-2026-72652 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-72644 | 6.5 MEDIUM | Uncaught Exception in Kibana Leading to Denial of Service |
| CVE-2026-72682 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-78605 | 5.9 MEDIUM | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch L |
| CVE-2026-78607 | 5.4 MEDIUM | Missing Authorization in Elasticsearch Leading to Information Disclosure |
| CVE-2026-72641 | 5.4 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data |
| CVE-2026-56143 | 4.9 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-72633 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin |
| CVE-2026-78603 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met |
| CVE-2026-78597 | 4.3 MEDIUM | Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation |
| CVE-2026-78606 | 4.2 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and De |
No comments yet