Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Kibana — Vulnerabilities & Security Advisories 154

All 154 CVE vulnerabilities found in Kibana, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumeration (CWE) vulnerabilities associated with the Kibana software product, developed by Elastic. It aggregates known security weaknesses that have been documented for this specific visualization and log management platform, providing a structured view of its historical security posture. The content collected here spans from the product’s initial releases through to the most recent updates, ensuring a comprehensive timeline of discovered flaws and their subsequent mitigations. By browsing this aggregation, users can effectively track vendor advisories issued by Elastic regarding specific security patches, understand the characteristics and potential impacts of distinct weakness classes such as buffer overflows or insecure defaults, and look up the detailed vulnerability history of Kibana to assess risk exposure over time. This resource serves as a centralized reference for security analysts, developers, and system administrators to evaluate the cumulative security landscape of the software without needing to search through disparate documentation sources individually. The focus remains strictly on factual data aggregation, presenting the evolution of identified weaknesses to facilitate informed decision-making regarding upgrade paths and configuration hardening. Readers are encouraged to review the chronological listings to identify patterns in vulnerability disclosure and remediation efforts, thereby gaining a clearer understanding of the long-term stability and security practices employed by the product maintainers. This approach allows for a thorough examination of how the software has addressed various security challenges across different versions, supporting proactive security management strategies within organizational environments that rely on Kibana for data analysis and monitoring.

Vendor: Elastic

CVE IDTitleCVSSSeverityPublished
CVE-2026-33461 Incorrect Authorization in Kibana Fleet Leading to Information Disclosure CWE-863 7.7 High2026-04-08
CVE-2026-4498 Execution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scope CWE-250 7.7 High2026-04-08
CVE-2026-26940 Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service CWE-1284 6.5 Medium2026-03-19
CVE-2026-26939 Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configuration CWE-862 6.5 Medium2026-03-19
CVE-2026-26938 Improper Neutralization of Special Elements Used in a Template Engine in Kibana Workflows Leading to Server-Side Request Forgery (SSRF) CWE-1336 8.6 High2026-02-26
CVE-2026-26937 Uncontrolled Resource Consumption in Kibana Leading to Denial of Service CWE-400 6.5 Medium2026-02-26
CVE-2026-26936 Inefficient Regular Expression Complexity in Kibana Leading to Denial of Service CWE-1333 4.9 Medium2026-02-26
CVE-2026-26935 Improper Input Validation in Kibana Leading to Denial of Service CWE-20 6.5 Medium2026-02-26
CVE-2026-26934 Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service CWE-1284 6.5 Medium2026-02-26
CVE-2026-0532 External Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Gemini Connector CWE-918 8.6 High2026-01-14
CVE-2026-0543 Improper Input Validation in Kibana Email Connector Leading to Excessive Allocation CWE-20 6.5 Medium2026-01-13
CVE-2026-0531 Allocation of Resources Without Limits or Throttling in Kibana Fleet CWE-770 6.5 Medium2026-01-13
CVE-2026-0530 Allocation of Resources Without Limits or Throttling in Kibana Leading to Excessive Allocation CWE-770 6.5 Medium2026-01-13
CVE-2025-68422 Kibana Improper Authorization CWE-863 4.3 Medium2025-12-18
CVE-2025-68386 Kibana Improper Authorization CWE-863 4.3 Medium2025-12-18
CVE-2025-68389 Kibana Allocation of Resources Without Limits or Throttling CWE-770 6.5 Medium2025-12-18
CVE-2025-68387 Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79 6.1 Medium2025-12-18
CVE-2025-68385 Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79 7.2 High2025-12-18
CVE-2025-37732 Kibana Cross-site Scripting via the Integration Package Upload Functionality CWE-79 5.4 Medium2025-12-15
CVE-2025-37734 Kibana Origin Validation Error CWE-346 4.3 Medium2025-11-12
CVE-2025-37735 Elastic Defend 安全漏洞 CWE-281 7.0 High2025-11-06
CVE-2025-25017 Kibana Stored Cross-Site Scripting (XSS) CWE-79 8.2 High2025-10-10
CVE-2025-25018 Kibana Stored Cross-Site Scripting (XSS) CWE-79 8.7 High2025-10-10
CVE-2025-25009 Kibana Cross-Site Scripting (XSS) CWE-79 8.7 High2025-10-07
CVE-2025-37728 Kibana Insufficiently Protected Credentials in the CrowdStrike Connector CWE-522 5.4 Medium2025-10-07
CVE-2025-25010 Kibana privilege escalation via reporting_user role CWE-863 6.5 Medium2025-08-28
CVE-2025-25012 Kibana Open Redirect CWE-601 4.3 Medium2025-06-25
CVE-2024-43706 Kibana Improper Authorization CWE-285 7.6 High2025-06-10
CVE-2025-25014 Kibana arbitrary code execution via prototype pollution CWE-1321 9.1 Critical2025-05-06
CVE-2024-11390 Kibana Unrestricted Upload of File with Dangerous Type Can Lead to XSS CWE-434 5.4 Medium2025-05-01

All 154 known CVE vulnerabilities affecting Kibana with full Chinese analysis, references, and POCs where available.