Kibana 中 Cribl 集成里的一个配置字段验证不足,允许持有 Kibana Fleet 管理权限的已认证用户将攻击者可控的表达式注入到服务器端的脚本模板中,从而导致生成的 Elasticsearch 摄取管道(ingest pipeline)超出了调用者所获授权的 Elasticsearch 权限范围。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82302 | 8.1 HIGH | Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification |
| CVE-2026-78583 | 8.1 HIGH | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-82299 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-82298 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Denial of Service |
| CVE-2026-78596 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations |
| CVE-2026-78595 | 4.3 MEDIUM | Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure |
No comments yet