Kibana 中存在通过用户可控键实现的授权绕过漏洞(CWE-639),可通过“访问未被访问控制列表(ACL)适当限制的功能”(CAPEC-1)导致数据遭未经授权的披露、修改和删除。在 Kibana 的某一空间中,被授予“时间线(Timeline)”功能权限的认证用户,能够枚举、读取、修改并删除同一空间内其他用户创建的草稿时间线对象。其中,读取权限足以实现枚举和数据披露;而时间线写入权限则用于执行修改和删除操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72668 | 7.3 HIGH | Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escala |
| CVE-2026-94397 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94396 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94400 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Kibana Leading to denial of service |
| CVE-2026-94399 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94398 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-82300 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-82294 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-78582 | 6.5 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Deletion of Data |
| CVE-2026-94408 | 4.9 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
No comments yet