以下是该漏洞描述的中文翻译: Elasticsearch 的自定义推理服务中存在缺失授权(CWE-862)问题,这可能通过权限滥用(CAPEC-122)导致信息泄露。仅持有推理执行权限的用户可以将出站推理流量引导至其自行选择的目标地址,并可能导致由管理员配置的凭据(Credentials)暴露出来。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 8.0.0≤ 8.19.18 |
affected |
9.0.0≤ 9.3.7 |
affected | ||
9.4.0≤ 9.4.3 |
affected | ||
9.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 8.0.0 ~ 8.19.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72649 | 8.8 HIGH | Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution |
| CVE-2026-63137 | 8.3 HIGH | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-78592 | 7.3 HIGH | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori |
| CVE-2024-14047 | 7.2 HIGH | Improper Link Resolution Before File Access ('Link Following') in Winlogbeat Leading to Ar |
| CVE-2026-78608 | 6.5 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-33465 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-63138 | 6.5 MEDIUM | Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Infor |
| CVE-2026-72654 | 6.5 MEDIUM | Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure |
| CVE-2026-72628 | 6.5 MEDIUM | Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service |
| CVE-2026-72652 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-72644 | 6.5 MEDIUM | Uncaught Exception in Kibana Leading to Denial of Service |
| CVE-2026-72682 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-78605 | 5.9 MEDIUM | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch L |
| CVE-2026-72641 | 5.4 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data |
| CVE-2026-56143 | 4.9 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-72633 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitorin |
| CVE-2026-78603 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Met |
| CVE-2026-78597 | 4.3 MEDIUM | Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation |
| CVE-2026-78606 | 4.2 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and De |
No comments yet