Kibana 中存在授权缺失漏洞(CWE-862),攻击者可通过利用配置不当的访问控制安全级别(CAPEC-180)实现未授权的数据删除。具体而言,持有针对单个 Kibana 工作区(space)范围权限的合成监控(Synthetics)权限的已认证用户,可能永久删除被共享至其无权访问的其他工作区中的合成监控。此外,当某个监控关联了私有位置(private location)时,该操作还会在缺乏 Fleet 通常应执行的授权检查的情况下,同时破坏底层的 Elastic Agent 集成配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72668 | 7.3 HIGH | Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escala |
| CVE-2026-94397 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94396 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94400 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Kibana Leading to denial of service |
| CVE-2026-94399 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94398 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-82300 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-82294 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-72662 | 6.3 MEDIUM | Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclos |
| CVE-2026-94408 | 4.9 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
No comments yet