Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Kibana — Vulnerabilities & Security Advisories 154

All 154 CVE vulnerabilities found in Kibana, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumeration (CWE) vulnerabilities associated with the Kibana software product, developed by Elastic. It aggregates known security weaknesses that have been documented for this specific visualization and log management platform, providing a structured view of its historical security posture. The content collected here spans from the product’s initial releases through to the most recent updates, ensuring a comprehensive timeline of discovered flaws and their subsequent mitigations. By browsing this aggregation, users can effectively track vendor advisories issued by Elastic regarding specific security patches, understand the characteristics and potential impacts of distinct weakness classes such as buffer overflows or insecure defaults, and look up the detailed vulnerability history of Kibana to assess risk exposure over time. This resource serves as a centralized reference for security analysts, developers, and system administrators to evaluate the cumulative security landscape of the software without needing to search through disparate documentation sources individually. The focus remains strictly on factual data aggregation, presenting the evolution of identified weaknesses to facilitate informed decision-making regarding upgrade paths and configuration hardening. Readers are encouraged to review the chronological listings to identify patterns in vulnerability disclosure and remediation efforts, thereby gaining a clearer understanding of the long-term stability and security practices employed by the product maintainers. This approach allows for a thorough examination of how the software has addressed various security challenges across different versions, supporting proactive security management strategies within organizational environments that rely on Kibana for data analysis and monitoring.

Vendor: Elastic

CVE IDTitleCVSSSeverityPublished
CVE-2026-63262 Missing Authorization in Kibana Leading to Information Disclosure CWE-862 4.3 Medium2026-07-21
CVE-2026-63261 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-07-21
CVE-2026-63260 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-07-21
CVE-2026-63259 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure CWE-639 4.3 Medium2026-07-21
CVE-2026-63145 Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise CWE-863 4.3 Medium2026-07-21
CVE-2026-63143 Missing Authorization in Kibana Leading to Unauthorized Information Disclosure CWE-862 4.3 Medium2026-07-21
CVE-2026-63142 Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery CWE-863 5.0 Medium2026-07-21
CVE-2026-63141 Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions CWE-862 6.3 Medium2026-07-21
CVE-2026-63139 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-07-21
CVE-2026-56147 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity Compromise CWE-639 7.1 High2026-07-21
CVE-2026-56146 Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure CWE-863 5.4 Medium2026-07-21
CVE-2026-42397 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service CWE-770 6.5 Medium2026-07-21
CVE-2026-49092 Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure CWE-863 4.3 Medium2026-07-21
CVE-2026-49091 Improper Output Neutralization for Logs in Kibana Leading to Log Injection CWE-116 8.0 High2026-07-01
CVE-2026-49088 Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosure CWE-532 4.4 Medium2026-07-01
CVE-2026-49087 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service CWE-770 6.5 Medium2026-07-01
CVE-2026-56151 Improper Input Validation in Kibana Leading to Denial of Service CWE-20 6.5 Medium2026-07-01
CVE-2026-49093 Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access CWE-918 6.3 Medium2026-05-28
CVE-2026-49094 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-05-28
CVE-2026-49095 Improper Input Validation in Kibana Fleet Leading to Privilege Escalation CWE-20 7.2 Medium2026-05-28
CVE-2026-42398 Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access CWE-918 7.7 High2026-05-28
CVE-2026-42399 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-05-28
CVE-2026-42400 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-05-28
CVE-2026-42401 Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored HTML Injection CWE-79 4.1 Medium2026-05-28
CVE-2026-33463 Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized File Access CWE-672 5.3 Medium2026-05-28
CVE-2026-33464 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-05-28
CVE-2026-33462 Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts CWE-22 4.6 Medium2026-05-28
CVE-2026-33458 Server-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information Disclosure CWE-918 6.8 Medium2026-04-08
CVE-2026-33459 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-04-08
CVE-2026-33460 Incorrect Authorization in Kibana Fleet Leading to Information Disclosure CWE-863 4.3 Medium2026-04-08

All 154 known CVE vulnerabilities affecting Kibana with full Chinese analysis, references, and POCs where available.