VendorsElastickibanaall versions
Vulnerabilities

Elastic Kibana

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

185CVEs
CVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Published 2019-03-25 · Analyzed
10.0KEVEPSS 0.953
CVE-2025-25015
Kibana arbitrary code execution via prototype pollution
Published 2025-03-05 · Analyzed
9.9EPSS 0.013
CVE-2024-37288
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-for-security.html  and have configured an Amazon Bedrock connector https://www.elastic.co/guide/en/security/current/assistant-connect-to-bedrock.html .
Published 2024-09-09 · Analyzed
9.9EPSS 0.010
CVE-2023-31415
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.
Published 2023-05-04 · Modified
9.9EPSS 0.010
CVE-2018-17246
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Published 2018-12-20 · Modified
9.8EPSS 0.823
CVE-2025-25014
Kibana arbitrary code execution via prototype pollution
Published 2025-05-06 · Analyzed
9.8EPSS 0.215
CVE-2018-17245
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.
Published 2018-12-20 · Modified
9.8EPSS 0.015
CVE-2024-12556
Kibana Prototype Pollution can lead to code injection
Published 2025-04-08 · Analyzed
9.8EPSS 0.005
CVE-2019-7610
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Published 2019-03-25 · Modified
9.3EPSS 0.039
CVE-2024-37287
Kibana arbitrary code execution via prototype pollution
Published 2024-08-13 · Analyzed
9.1EPSS 0.016
CVE-2024-37285
Kibana arbitrary code execution via YAML deserialization
Published 2024-11-14 · Analyzed
9.1EPSS 0.012
CVE-2026-72676
Improper Control of Generation of Code in Fleet Server Leading to Code Injection
Published 2026-08-13 · Analyzed
9.1EPSS 0.005
CVE-2023-31422
Kibana Insertion of Sensitive Information into Log File
Published 2023-10-26 · Modified
9.0EPSS 0.008
CVE-2020-7012
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.
Published 2020-06-03 · Modified
8.8EPSS 0.182
CVE-2021-22142
Kibana Reporting vulnerabilities
Published 2023-11-22 · Modified
8.8EPSS 0.010
CVE-2023-31414
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.
Published 2023-05-04 · Modified
8.8EPSS 0.006
CVE-2024-43706
Kibana Improper Authorization
Published 2025-06-10 · Analyzed
8.8EPSS 0.004
CVE-2026-72681
Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure
Published 2026-08-13 · Analyzed
8.8EPSS 0.004
CVE-2025-25009
Kibana Cross-Site Scripting (XSS)
Published 2025-10-07 · Analyzed
8.7EPSS 0.002
CVE-2025-25018
Kibana Stored Cross-Site Scripting (XSS)
Published 2025-10-10 · Analyzed
8.7EPSS 0.002
CVE-2026-26938
Improper Neutralization of Special Elements Used in a Template Engine in Kibana Workflows Leading to Server-Side Request Forgery (SSRF)
Published 2026-02-26 · Analyzed
8.6EPSS 0.004
CVE-2026-63137
Incorrect Authorization in Kibana Leading to Privilege Escalation
Published 2026-09-01 · Analyzed
8.3EPSS 0.005
CVE-2025-25017
Kibana Stored Cross-Site Scripting (XSS)
Published 2025-10-10 · Analyzed
8.2EPSS 0.003
CVE-2026-72665
Missing Authorization in Kibana Leading to Unauthorized Execution of Host Response Actions
Published 2026-08-13 · Analyzed
8.1EPSS 0.005
CVE-2026-78583
Incorrect Authorization in Kibana Leading to Privilege Escalation
Published 2026-09-03 · Analyzed
8.1EPSS 0.004
CVE-2023-46675
Kibana Insertion of Sensitive Information into Log File
Published 2023-12-13 · Modified
8.0EPSS 0.007
CVE-2023-46671
Kibana Insertion of Sensitive Information into Log File
Published 2023-12-13 · Modified
8.0EPSS 0.007
CVE-2026-49091
Improper Output Neutralization for Logs in Kibana Leading to Log Injection
Published 2026-07-01 · Analyzed
8.0EPSS 0.003
CVE-2026-4498
Execution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scope
Published 2026-04-08 · Analyzed
7.7EPSS 0.005
CVE-2026-72670
Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials
Published 2026-08-13 · Analyzed
7.7EPSS 0.005
CVE-2026-33461
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
Published 2026-04-08 · Analyzed
7.7EPSS 0.005
CVE-2024-43707
Kibana exposure of sensitive information to an unauthorized actor
Published 2025-01-23 · Analyzed
7.7EPSS 0.004
CVE-2026-42398
Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access
Published 2026-05-28 · Analyzed
7.7EPSS 0.004
CVE-2026-33458
Server-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information Disclosure
Published 2026-04-08 · Analyzed
7.7EPSS 0.004
CVE-2026-72672
Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event Data
Published 2026-08-13 · Analyzed
7.7EPSS 0.004
CVE-2026-49093
Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access
Published 2026-05-28 · Analyzed
7.7EPSS 0.003
CVE-2026-72669
Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tampering
Published 2026-08-13 · Analyzed
7.6EPSS 0.003
CVE-2016-1000219
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.
Published 2017-06-16 · Modified
7.5EPSS 0.020
CVE-2017-8452
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.
Published 2017-06-16 · Modified
7.5EPSS 0.014
CVE-2026-26936
Inefficient Regular Expression Complexity in Kibana Leading to Denial of Service
Published 2026-02-26 · Analyzed
7.5EPSS 0.005
1 / 5Next →