Kibana 实体存储(Entity Store)功能中存在授权缺失(CWE-862)问题,可能通过“访问未受访问控制列表(ACL)适当约束的功能”(CAPEC-1)导致非授权的凭证创建。仅拥有低权限“Security”功能访问权限的已认证用户,可以调用一个管理操作,以调用者身份创建并持久化 Elasticsearch API 密钥,从而绕过文档中描述的实体存储设置流程所要求的高级集群和 Kibana 权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72649 | 8.8 HIGH | Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution |
| CVE-2026-63137 | 8.3 HIGH | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-78592 | 7.3 HIGH | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori |
| CVE-2024-14047 | 7.2 HIGH | Improper Link Resolution Before File Access ('Link Following') in Winlogbeat Leading to Ar |
| CVE-2026-78608 | 6.5 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-33465 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-63138 | 6.5 MEDIUM | Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Infor |
| CVE-2026-72654 | 6.5 MEDIUM | Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure |
| CVE-2026-72628 | 6.5 MEDIUM | Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service |
| CVE-2026-72652 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-72644 | 6.5 MEDIUM | Uncaught Exception in Kibana Leading to Denial of Service |
| CVE-2026-72682 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-78605 | 5.9 MEDIUM | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch L |
| CVE-2026-78607 | 5.4 MEDIUM | Missing Authorization in Elasticsearch Leading to Information Disclosure |
| CVE-2026-72641 | 5.4 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data |
| CVE-2026-56143 | 4.9 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-72633 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin |
| CVE-2026-78603 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met |
| CVE-2026-78606 | 4.2 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and De |
No comments yet