Elastic kibana是荷兰Elastic公司开源的一个数据可视化平台。 Elastic Kibana 9.0.0至9.3.3及之前版本和8.0.0至8.19.14及之前版本存在资源管理错误漏洞,该漏洞源于资源无限制分配,可能导致经过身份验证的用户通过提交特制批量删除请求造成过多资源消耗,进而导致拒绝服务。以下版本受到影响:9.0.0至9.3.3及之前版本和8.0.0至8.19.14及之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49091 | 8.0 HIGH | Improper Output Neutralization for Logs in Kibana Leading to Log Injection |
| CVE-2026-49090 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-56150 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of |
| CVE-2026-56148 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-56151 | 6.5 MEDIUM | Improper Input Validation in Kibana Leading to Denial of Service |
| CVE-2026-56152 | 5.3 MEDIUM | Incorrect Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-56149 | 4.9 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-49088 | 4.4 MEDIUM | Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosu |
No comments yet