VendorsElastickibanaall versions
Vulnerabilities

Elastic Kibana

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

185CVEs
CVE-2022-23709
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.
Published 2022-03-03 · Modified
4.3EPSS 0.006
CVE-2024-37279
Kibana Broken Access Control issue
Published 2024-06-13 · Modified
4.3EPSS 0.004
CVE-2026-72650
Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure
Published 2026-08-13 · Analyzed
4.3EPSS 0.003
CVE-2026-63143
Missing Authorization in Kibana Leading to Unauthorized Information Disclosure
Published 2026-07-21 · Analyzed
4.3EPSS 0.003
CVE-2025-25016
Kibana Unrestricted Upload of File
Published 2025-05-01 · Analyzed
4.3EPSS 0.003
CVE-2026-78584
Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
Published 2026-09-02 · Analyzed
4.3EPSS 0.003
CVE-2026-72655
Improperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data Modification
Published 2026-08-13 · Analyzed
4.3EPSS 0.003
CVE-2026-49096
Uncaught Exception in Kibana Cases Leading to Denial of Service
Published 2026-08-13 · Analyzed
4.3EPSS 0.003
CVE-2026-78597
Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key Creation
Published 2026-09-01 · Analyzed
4.3EPSS 0.003
CVE-2026-78603
Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Metadata
Published 2026-09-01 · Analyzed
4.3EPSS 0.003
CVE-2026-63259
Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure
Published 2026-07-21 · Analyzed
4.3EPSS 0.003
CVE-2026-33460
Incorrect Authorization in Kibana Fleet Leading to Information Disclosure
Published 2026-04-08 · Analyzed
4.3EPSS 0.003
CVE-2026-63262
Missing Authorization in Kibana Leading to Information Disclosure
Published 2026-07-21 · Analyzed
4.3EPSS 0.003
CVE-2026-49092
Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure
Published 2026-07-21 · Analyzed
4.3EPSS 0.003
CVE-2026-72633
Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitoring
Published 2026-09-01 · Analyzed
4.3EPSS 0.003
CVE-2026-63145
Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise
Published 2026-07-21 · Analyzed
4.3EPSS 0.003
CVE-2026-72671
Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments
Published 2026-08-13 · Analyzed
4.3EPSS 0.003
CVE-2024-43710
Kibana server-side request forgery
Published 2025-01-23 · Analyzed
4.3EPSS 0.003
CVE-2025-68422
Kibana Improper Authorization
Published 2025-12-18 · Analyzed
4.3EPSS 0.002
CVE-2025-37734
Kibana Origin Validation Error
Published 2025-11-12 · Analyzed
4.3EPSS 0.002
CVE-2025-68386
Kibana Improper Authorization
Published 2025-12-18 · Analyzed
4.3EPSS 0.002
CVE-2026-78606
Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data
Published 2026-09-01 · Analyzed
4.2EPSS 0.002
CVE-2026-78581
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana
Published 2026-08-25 · Analyzed
4.2EPSS 0.002
CVE-2021-37939
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.
Published 2021-11-18 · Modified
4.0EPSS 0.005
CVE-2021-22136
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.
Published 2021-05-13 · Modified
3.6EPSS 0.003
← Prev5 / 5