VendorsElastickibanaany version
Vulnerabilities

Elastic Kibana any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

172CVEs
CVE-2026-63262
Missing Authorization in Kibana Leading to Information Disclosure
Published 2026-07-21 · Analyzed
4.3EPSS 0.003
CVE-2026-72671
Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments
Published 2026-08-13 · Analyzed
4.3EPSS 0.003
CVE-2026-63145
Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise
Published 2026-07-21 · Analyzed
4.3EPSS 0.003
CVE-2026-72633
Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitoring
Published 2026-09-01 · Analyzed
4.3EPSS 0.003
CVE-2024-43710
Kibana server-side request forgery
Published 2025-01-23 · Analyzed
4.3EPSS 0.003
CVE-2025-68422
Kibana Improper Authorization
Published 2025-12-18 · Analyzed
4.3EPSS 0.002
CVE-2025-37734
Kibana Origin Validation Error
Published 2025-11-12 · Analyzed
4.3EPSS 0.002
CVE-2025-68386
Kibana Improper Authorization
Published 2025-12-18 · Analyzed
4.3EPSS 0.002
CVE-2026-78606
Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data
Published 2026-09-01 · Analyzed
4.2EPSS 0.002
CVE-2026-78581
Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Data Modification in Kibana
Published 2026-08-25 · Analyzed
4.2EPSS 0.002
CVE-2021-37939
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could utilize these connectors to view limited HTTP response data on hosts accessible to the cluster.
Published 2021-11-18 · Modified
4.0EPSS 0.005
CVE-2021-22136
In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caused by background polling activities unintentionally extending authenticated users sessions, preventing a user session from timing out.
Published 2021-05-13 · Modified
3.6EPSS 0.003
← Prev5 / 5