Kibana 中存在的“缺失授权检查”(CWE-862)漏洞,可能导致通过“访问未受访问控制列表(ACL)充分限制的功能”(CAPEC-1)造成信息泄露。Metrics Experience(指标体验)功能内部存在一个 API 接口,该接口未强制执行 Kibana 层面的授权检查,而同一功能中另一个等效且相关的 API 则正确实施了此类检查。因此,若用户仅拥有对某个数据索引的数据存储级读取权限,但缺乏相应的 Kibana 功能级权限,仍可通过该未授权 API 获取由该索引衍生的指标数据,而这些数据本应被具备适当授权
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102406 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data In |
| CVE-2026-103007 | 7.2 HIGH | Incorrect Authorization in Elasticsearch Leading to Privilege Escalation |
| CVE-2026-103009 | 7.1 HIGH | Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information D |
| CVE-2026-102412 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure |
| CVE-2026-102409 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102411 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-102404 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-103008 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-103005 | 6.5 MEDIUM | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
| CVE-2026-103006 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102413 | 6.2 MEDIUM | Uncaught Exception in Elastic Endpoint Leading to Denial of Service |
| CVE-2026-102407 | 5.4 MEDIUM | Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification |
| CVE-2026-102408 | 4.3 MEDIUM | Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service |
No comments yet