Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

kibana — Vulnerabilities & Security Advisories 154

All 154 CVE vulnerabilities found in kibana, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumeration (CWE) vulnerabilities associated with the Kibana software product, developed by Elastic. It aggregates known security weaknesses that have been documented for this specific visualization and log management platform, providing a structured view of its historical security posture. The content collected here spans from the product’s initial releases through to the most recent updates, ensuring a comprehensive timeline of discovered flaws and their subsequent mitigations. By browsing this aggregation, users can effectively track vendor advisories issued by Elastic regarding specific security patches, understand the characteristics and potential impacts of distinct weakness classes such as buffer overflows or insecure defaults, and look up the detailed vulnerability history of Kibana to assess risk exposure over time. This resource serves as a centralized reference for security analysts, developers, and system administrators to evaluate the cumulative security landscape of the software without needing to search through disparate documentation sources individually. The focus remains strictly on factual data aggregation, presenting the evolution of identified weaknesses to facilitate informed decision-making regarding upgrade paths and configuration hardening. Readers are encouraged to review the chronological listings to identify patterns in vulnerability disclosure and remediation efforts, thereby gaining a clearer understanding of the long-term stability and security practices employed by the product maintainers. This approach allows for a thorough examination of how the software has addressed various security challenges across different versions, supporting proactive security management strategies within organizational environments that rely on Kibana for data analysis and monitoring.

Vendor: Elastic

CVE IDTitleCVSSSeverityPublished
CVE-2026-49096 Uncaught Exception in Kibana Cases Leading to Denial of Service CWE-248 4.3 Medium2026-08-13
CVE-2026-72632 Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API Keys CWE-203 7.1 High2026-08-13
CVE-2026-72631 Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Keys CWE-269 6.5 Medium2026-08-13
CVE-2026-72630 Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation CWE-863 7.1 High2026-08-13
CVE-2026-72629 Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models CWE-639 7.1 High2026-08-13
CVE-2026-72643 Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents CWE-863 7.1 High2026-08-13
CVE-2026-72655 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data Modification CWE-915 4.3 Medium2026-08-13
CVE-2026-72653 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service CWE-770 6.5 Medium2026-08-13
CVE-2026-72651 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service CWE-770 6.5 Medium2026-08-13
CVE-2026-72650 Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure CWE-639 4.3 Medium2026-08-13
CVE-2026-72663 Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service CWE-407 6.5 Medium2026-08-13
CVE-2026-72661 Missing Authorization in Kibana Leading to Information Disclosure CWE-862 6.5 Medium2026-08-13
CVE-2026-72660 Uncaught Exception in Kibana Leading to Denial of Service CWE-248 6.5 Medium2026-08-13
CVE-2026-72659 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service CWE-770 6.5 Medium2026-08-13
CVE-2026-72658 Cross-Site Request Forgery in Kibana Leading to Privilege Escalation CWE-352 7.3 High2026-08-13
CVE-2026-72667 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service CWE-770 6.5 Medium2026-08-13
CVE-2026-72666 Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts CWE-639 6.8 Medium2026-08-13
CVE-2026-72665 Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions CWE-862 8.1 High2026-08-13
CVE-2026-72664 Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions CWE-862 6.5 Medium2026-08-13
CVE-2026-72677 Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources CWE-23 7.3 High2026-08-13
CVE-2026-72675 Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification CWE-862 7.1 High2026-08-13
CVE-2026-72674 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service CWE-770 6.5 Medium2026-08-13
CVE-2026-72673 Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private Locations CWE-863 5.4 Medium2026-08-13
CVE-2026-72672 Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event Data CWE-863 7.7 High2026-08-13
CVE-2026-72671 Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments CWE-862 4.3 Medium2026-08-13
CVE-2026-72670 Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials CWE-200 7.7 High2026-08-13
CVE-2026-72669 Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tampering CWE-862 7.6 High2026-08-13
CVE-2026-72681 Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure CWE-862 6.5 Medium2026-08-13
CVE-2026-72680 Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data Modification CWE-639 6.5 Medium2026-08-13
CVE-2026-49089 Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service CWE-770 6.5 Medium2026-08-13

All 154 known CVE vulnerabilities affecting kibana with full Chinese analysis, references, and POCs where available.