VendorsElastickibanaany version
Vulnerabilities

Elastic Kibana any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

172CVEs
CVE-2026-0543
Improper Input Validation in Kibana Email Connector Leading to Excessive Allocation
Published 2026-01-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72682
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-09-01 · Analyzed
6.5EPSS 0.004
CVE-2026-72644
Uncaught Exception in Kibana Leading to Denial of Service
Published 2026-09-01 · Analyzed
6.5EPSS 0.004
CVE-2026-72652
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-09-01 · Analyzed
6.5EPSS 0.004
CVE-2026-72674
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-42397
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.004
CVE-2026-72667
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72659
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72651
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72653
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-33465
Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service
Published 2026-09-01 · Analyzed
6.5EPSS 0.004
CVE-2026-72663
Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2024-37281
Kibana Denial of Service issue
Published 2024-07-30 · Analyzed
6.5EPSS 0.004
CVE-2024-52974
An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack requires a malicious user to have read permissions for Observability assigned to them.
Published 2025-04-08 · Analyzed
6.5EPSS 0.004
CVE-2026-72664
Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response Actions
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72661
Missing Authorization in Kibana Leading to Information Disclosure
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-78608
Missing Authorization in Kibana Leading to Information Disclosure
Published 2026-09-01 · Analyzed
6.5EPSS 0.004
CVE-2024-43708
An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in Kibana UI. This can be carried out by users with read access to any feature in Kibana.
Published 2025-01-23 · Analyzed
6.5EPSS 0.004
CVE-2024-52972
Kibana allocation of resources without limits or throttling leads to crash
Published 2025-01-23 · Analyzed
6.5EPSS 0.004
CVE-2024-52973
Kibana allocation of resources without limits or throttling leads to crash
Published 2025-01-21 · Analyzed
6.5EPSS 0.004
CVE-2026-26939
Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configuration
Published 2026-03-19 · Analyzed
6.5EPSS 0.003
CVE-2026-72631
Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Keys
Published 2026-08-13 · Analyzed
6.5EPSS 0.003
CVE-2026-0530
Allocation of Resources Without Limits or Throttling in Kibana Leading to Excessive Allocation
Published 2026-01-13 · Analyzed
6.5EPSS 0.003
CVE-2025-68389
Kibana Allocation of Resources Without Limits or Throttling
Published 2025-12-18 · Analyzed
6.5EPSS 0.003
CVE-2025-25010
Kibana privilege escalation via reporting_user role
Published 2025-08-28 · Analyzed
6.5EPSS 0.003
CVE-2026-72680
Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data Modification
Published 2026-08-13 · Analyzed
6.5EPSS 0.003
CVE-2026-78591
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource Deletion
Published 2026-09-02 · Analyzed
6.3EPSS 0.004
CVE-2026-63141
Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions
Published 2026-07-21 · Analyzed
6.3EPSS 0.002
CVE-2018-3830
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Published 2018-09-19 · Modified
6.1EPSS 0.016
CVE-2019-7608
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Published 2019-03-25 · Modified
6.1EPSS 0.013
CVE-2016-1000220
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
Published 2017-06-16 · Modified
6.1EPSS 0.012
CVE-2018-3818
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Published 2018-03-30 · Modified
6.1EPSS 0.010
CVE-2016-10365
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
Published 2017-06-16 · Modified
6.1EPSS 0.010
CVE-2017-8451
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Published 2017-06-16 · Modified
6.1EPSS 0.009
CVE-2018-3821
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Published 2018-03-30 · Modified
6.1EPSS 0.009
CVE-2018-3820
Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
Published 2018-03-30 · Modified
6.1EPSS 0.008
CVE-2018-3819
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Published 2018-03-30 · Modified
6.1EPSS 0.008
CVE-2022-23713
A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.
Published 2022-07-06 · Modified
6.1EPSS 0.008
CVE-2015-9056
Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.
Published 2017-06-16 · Modified
6.1EPSS 0.008
CVE-2022-23710
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.
Published 2022-03-03 · Modified
6.1EPSS 0.008
← Prev3 / 5Next →