VendorsElastickibana9.5.0
Vulnerabilities

Elastic Kibana 9.5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-72676
Improper Control of Generation of Code in Fleet Server Leading to Code Injection
Published 2026-08-13 · Analyzed
9.1EPSS 0.005
CVE-2026-72629
Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained Models
Published 2026-08-13 · Analyzed
7.1EPSS 0.004
CVE-2026-72643
Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private Agents
Published 2026-08-13 · Analyzed
7.1EPSS 0.004
CVE-2026-72632
Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API Keys
Published 2026-08-13 · Analyzed
7.1EPSS 0.003
CVE-2026-72630
Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation
Published 2026-08-13 · Analyzed
7.1EPSS 0.003
CVE-2026-63138
Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure
Published 2026-09-01 · Analyzed
6.5EPSS 0.005
CVE-2026-72644
Uncaught Exception in Kibana Leading to Denial of Service
Published 2026-09-01 · Analyzed
6.5EPSS 0.004
CVE-2026-72631
Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Keys
Published 2026-08-13 · Analyzed
6.5EPSS 0.003
CVE-2026-72641
Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data
Published 2026-09-01 · Analyzed
5.4EPSS 0.003
CVE-2026-78603
Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Metadata
Published 2026-09-01 · Analyzed
4.3EPSS 0.003