Kibana Agent Builder 中存在非预期的代理或中间人(“混淆 deputy”)漏洞(CWE-441),可能导致权限提升。一个非管理员用户如果能够编辑共享的代理,则可能以更高权限用户的身份执行特权操作,而该高权限用户随后会与代理进行交互。如果同一用户还能创建工作流,则此漏洞可能导致对 Kibana 和 Elasticsearch 集群的完全控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94397 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94396 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94400 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Kibana Leading to denial of service |
| CVE-2026-94399 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94398 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-82300 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-82294 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-78582 | 6.5 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Deletion of Data |
| CVE-2026-72662 | 6.3 MEDIUM | Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclos |
| CVE-2026-94408 | 4.9 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
No comments yet