这段描述了一个存在于 Kibana 中的安全漏洞,核心问题是缺少授权检查,导致用户能够进行其权限范围之外的写操作。以下是该段落的中文翻译: Kibana 中缺少授权导致数据被未授权修改 / Kibana 中缺少授权(CWE-862)可能导致数据被未授权修改,进而通过权限滥用(CAPEC-122)造成影响。具体而言,在单个 Kibana 空间中仅拥有安全读取(Security read)权限的已认证用户,可以触发实体分析(Entity Analytics)迁移操作;这些迁移操作会在所有 Kibana 空间中执行具有较
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82302 | 8.1 HIGH | Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification |
| CVE-2026-78583 | 8.1 HIGH | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-82299 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-82298 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Denial of Service |
| CVE-2026-78595 | 4.3 MEDIUM | Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure |
| CVE-2026-78593 | 4.3 MEDIUM | Improper Control of Generation of Code in Kibana Leading to Privilege Escalation |
No comments yet