Elastic Defend是荷兰Elastic公司的一款应用程序。提供预防、检测和响应功能,以及对 EPP、EDR、SIEM 和安全分析的深度可见性。 Elastic Defend存在授权问题漏洞,该漏洞源于授权不正确,可能导致低权限认证用户访问未经授权的响应操作数据,从而造成信息泄露。以下版本受到影响:8.6.0至8.19.12版本、9.0.0至9.2.6版本、9.3.0至9.3.1版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49091 | 8.0 HIGH | Improper Output Neutralization for Logs in Kibana Leading to Log Injection |
| CVE-2026-49090 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-49087 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-56150 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of |
| CVE-2026-56148 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-56151 | 6.5 MEDIUM | Improper Input Validation in Kibana Leading to Denial of Service |
| CVE-2026-56149 | 4.9 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-49088 | 4.4 MEDIUM | Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosu |
No comments yet