VendorsElastickibanaany version
Vulnerabilities

Elastic Kibana any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

172CVEs
CVE-2026-78592
Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources
Published 2026-09-01 · Analyzed
7.3EPSS 0.004
CVE-2026-72677
Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other Resources
Published 2026-08-13 · Analyzed
7.3EPSS 0.004
CVE-2026-33462
Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts
Published 2026-05-28 · Analyzed
7.3EPSS 0.004
CVE-2026-72658
Cross-Site Request Forgery in Kibana Leading to Privilege Escalation
Published 2026-08-13 · Analyzed
7.3EPSS 0.002
CVE-2020-7013
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.
Published 2020-06-03 · Modified
7.2EPSS 0.021
CVE-2021-22150
Kibana code execution issue
Published 2023-11-22 · Modified
7.2EPSS 0.012
CVE-2025-68385
Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published 2025-12-18 · Analyzed
7.2EPSS 0.003
CVE-2026-72629
Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models
Published 2026-08-13 · Analyzed
7.1EPSS 0.004
CVE-2026-72643
Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents
Published 2026-08-13 · Analyzed
7.1EPSS 0.004
CVE-2026-72632
Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API Keys
Published 2026-08-13 · Analyzed
7.1EPSS 0.003
CVE-2026-56147
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity Compromise
Published 2026-07-21 · Analyzed
7.1EPSS 0.003
CVE-2026-72675
Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification
Published 2026-08-13 · Analyzed
7.1EPSS 0.003
CVE-2026-72630
Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation
Published 2026-08-13 · Analyzed
7.1EPSS 0.003
CVE-2015-8131
Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Published 2015-12-07 · Modified
6.8EPSS 0.009
CVE-2026-72666
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed Hosts
Published 2026-08-13 · Analyzed
6.8EPSS 0.004
CVE-2017-8443
In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen, the credentials will appear in the URL bar. The credentials could then be viewed by untrusted parties or logged into the Kibana access logs.
Published 2017-06-30 · Modified
6.5EPSS 0.011
CVE-2021-22139
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.
Published 2021-05-13 · Modified
6.5EPSS 0.010
CVE-2022-38778
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
Published 2023-02-08 · Modified
6.5EPSS 0.009
CVE-2026-72660
Uncaught Exception in Kibana Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.005
CVE-2026-72654
Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure
Published 2026-09-01 · Analyzed
6.5EPSS 0.005
CVE-2024-23446
Kibana Broken Access Control issue
Published 2024-02-07 · Modified
6.5EPSS 0.005
CVE-2026-26934
Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service
Published 2026-02-26 · Analyzed
6.5EPSS 0.005
CVE-2026-78599
Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources
Published 2026-09-02 · Analyzed
6.5EPSS 0.005
CVE-2026-0531
Allocation of Resources Without Limits or Throttling in Kibana Fleet
Published 2026-01-13 · Analyzed
6.5EPSS 0.005
CVE-2026-63261
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.005
CVE-2026-42399
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published 2026-05-28 · Analyzed
6.5EPSS 0.005
CVE-2026-49087
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-07-01 · Analyzed
6.5EPSS 0.005
CVE-2026-26940
Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service
Published 2026-03-19 · Analyzed
6.5EPSS 0.005
CVE-2026-63260
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.005
CVE-2026-49094
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published 2026-05-28 · Analyzed
6.5EPSS 0.005
CVE-2026-56151
Improper Input Validation in Kibana Leading to Denial of Service
Published 2026-07-01 · Analyzed
6.5EPSS 0.005
CVE-2026-78586
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-09-02 · Analyzed
6.5EPSS 0.005
CVE-2026-72628
Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service
Published 2026-09-01 · Analyzed
6.5EPSS 0.005
CVE-2026-33459
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published 2026-04-08 · Analyzed
6.5EPSS 0.005
CVE-2026-49089
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.005
CVE-2026-63139
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.005
CVE-2026-33464
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published 2026-05-28 · Analyzed
6.5EPSS 0.005
CVE-2026-42400
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Published 2026-05-28 · Analyzed
6.5EPSS 0.005
CVE-2026-63138
Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure
Published 2026-09-01 · Analyzed
6.5EPSS 0.005
CVE-2026-49095
Improper Input Validation in Kibana Fleet Leading to Privilege Escalation
Published 2026-05-28 · Analyzed
6.5EPSS 0.005
← Prev2 / 5Next →