Elastic kibana是荷兰Elastic公司开源的一个数据可视化平台。 Kibana 9.0.0版本至9.3.7版本、8.0.0版本至8.19.18版本和9.4.0版本至9.4.3版本存在资源管理错误漏洞,该漏洞源于资源消耗不受控制,可能导致经过身份验证的低权限攻击者通过发送特制超大请求有效负载,导致资源密集型内存分配耗尽堆内存,造成Kibana崩溃并拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56147 | 7.1 HIGH | Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Informa |
| CVE-2026-42397 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-63263 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-63261 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-63144 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-63140 | 6.5 MEDIUM | Reachable Assertion in Elasticsearch Leading to Denial of Service |
| CVE-2026-63136 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-63139 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Kibana Leading to Denial of Service |
| CVE-2026-56145 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-63141 | 6.3 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management |
| CVE-2026-56146 | 5.4 MEDIUM | Improper Access Control in Kibana Leading to Unauthorized Data Modification and Informatio |
| CVE-2026-56144 | 5.3 MEDIUM | Incorrect Authorization in Elasticsearch Leading to Information Disclosure |
| CVE-2026-63142 | 5.0 MEDIUM | Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery |
| CVE-2026-63143 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Information Disclosure |
| CVE-2026-63259 | 4.3 MEDIUM | Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosu |
| CVE-2026-63145 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromi |
| CVE-2026-63262 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-49092 | 4.3 MEDIUM | Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Inf |
No comments yet