Kibana 缺少授权检查,导致信息泄露 Kibana 的 Fleet 功能中存在缺失授权检查的问题(CWE-862),可能通过权限滥用(CAPEC-122)导致信息泄露。具体来说,在 Kibana 的某个 Space 中拥有 Fleet 代理只读权限的已认证用户,能够枚举并访问归属于其他 Kibana Space 中已注册代理的诊断内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82302 | 8.1 HIGH | Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification |
| CVE-2026-78583 | 8.1 HIGH | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-82299 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-82298 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Denial of Service |
| CVE-2026-78596 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations |
| CVE-2026-78593 | 4.3 MEDIUM | Improper Control of Generation of Code in Kibana Leading to Privilege Escalation |
No comments yet