Kibana 中的错误授权(CWE-863)可能导致通过利用错误配置的访问控制安全级别(CAPEC-180)引发服务拒绝(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82302 | 8.1 HIGH | Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification |
| CVE-2026-78583 | 8.1 HIGH | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-82299 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-78596 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations |
| CVE-2026-78595 | 4.3 MEDIUM | Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure |
| CVE-2026-78593 | 4.3 MEDIUM | Improper Control of Generation of Code in Kibana Leading to Privilege Escalation |
No comments yet