Elastic Elastic
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Elastic product.
RSS Feeds for Elastic security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Elastic products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Elastic Sorted by Most Security Vulnerabilities since 2018
Known Exploited Elastic Vulnerabilities
The following Elastic vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability |
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands. CVE-2015-1427 Exploit Probability: 99.9% |
March 25, 2022 |
| Elasticsearch Remote Code Execution Vulnerability |
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code. CVE-2014-3120 Exploit Probability: 88.6% |
March 25, 2022 |
| Kibana Arbitrary Code Execution |
Kibana contain an arbitrary code execution flaw in the Timelion visualizer. CVE-2019-7609 Exploit Probability: 95.3% |
January 10, 2022 |
Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 152 vulnerabilities in Elastic with an average score of 6.2 out of ten. Last year, in 2025 Elastic had 41 security vulnerabilities published. That is, 111 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.55
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 152 | 6.17 |
| 2025 | 41 | 6.72 |
| 2024 | 19 | 6.44 |
| 2023 | 31 | 6.95 |
| 2022 | 11 | 5.66 |
| 2021 | 21 | 5.76 |
| 2020 | 13 | 6.10 |
| 2019 | 14 | 8.38 |
| 2018 | 20 | 7.11 |
It may take a day or so for new Elastic vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Elastic Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-82302 | Sep 03, 2026 |
Kibana Unauthorized Config Mod via Incorrect Authorization (CWE-863)Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). |
|
| CVE-2026-82299 | Sep 03, 2026 |
Kibana Incorrect Auth (CWE-863) Enables Info DisclosureIncorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). |
|
| CVE-2026-82298 | Sep 03, 2026 |
Kibana Incorrect Authorization Leading to DoS via Misconfigured Access ControlIncorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). |
|
| CVE-2026-78596 | Sep 03, 2026 |
Kibana Missing Auth: Unauthorized Data Mod via Space MigrationMissing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope. |
|
| CVE-2026-78595 | Sep 03, 2026 |
Missing Auth in Kibana Fleet: Read-Only Agent Credentials LeakMissing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and access diagnostic content belonging to agents enrolled in other Kibana spaces. |
|
| CVE-2026-78593 | Sep 03, 2026 |
Kibana Cribl RCE via Insufficient Validation of Config FieldAn insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized Elasticsearch permissions. |
|
| CVE-2026-78583 | Sep 03, 2026 |
CVE-2026-78583: Kibana Privilege Escalation via Unvalidated Agent CredentialsIncorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration. |
|
| CVE-2026-82293 | Sep 02, 2026 |
Kibana ML Feature - Incorrect Auth. Enables Unauthorized Resource ConsumptionIncorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster resources they should not be able to reach. |
|
| CVE-2026-78588 | Sep 02, 2026 |
Filebeat HTTP ingestion endpoint allows unchecked memory allocationAllocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process. |
|
| CVE-2026-78587 | Sep 02, 2026 |
Fleet Server Auth Bypass Enables Agent Upload Denial of ServiceIncorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to interfere with the active upload sessions belonging to other enrolled agents. |
|
| CVE-2026-78586 | Sep 02, 2026 |
Kibana Unbounded Memory Allocation Leads to DoS by Low-Priv Auth UserAllocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users. |
|
| CVE-2026-78584 | Sep 02, 2026 |
Kibana Osquery LiveQuery Disclosure via Identifier ExistenceObservable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access. |
|
| CVE-2026-78591 | Sep 02, 2026 |
Kibana Fleet Path Traversal leads to unauthorized deletionImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges. |
|
| CVE-2026-78590 | Sep 02, 2026 |
Elastic Kibana Fleet Path Traversal Deletion VulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged resources such as user accounts and other organizational assets. Exploitation requires an administrator to interact with the affected Fleet interface. |
|
| CVE-2026-78599 | Sep 02, 2026 |
Kibana Fleet Path Traversal Violation Leads to DeletionImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface. |
|
| CVE-2026-78598 | Sep 02, 2026 |
Kibana ML Job Auth Escalation: CrossSpace Data ExposureIncorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces. |
|
| CVE-2026-78594 | Sep 02, 2026 |
APM Server Denial via Highly Compressed Source Map (CWE409/CAPEC130)Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed. |
|
| CVE-2026-78604 | Sep 02, 2026 |
Elastic Agent: Incorrect Perm. Assignment Causing Local Priv EscalationIncorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host. |
|
| CVE-2026-78602 | Sep 02, 2026 |
Elastic Maps Server Path Traversal can expose file contentsImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the contents of files outside its intended content directory that are readable by the server process. |
|
| CVE-2026-78601 | Sep 02, 2026 |
Kibana Entity Store Auth Bypass Exposes DataMissing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from Elasticsearch indices that user is not authorized to access. Derived entity data from those indices is then exposed through the entity store output. |
|
| CVE-2026-78600 | Sep 02, 2026 |
ECK Incomplete Cleanup Enables LowPrivileged Privilege AbuseIncomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster. |
|
| CVE-2026-78609 | Sep 02, 2026 |
Incorrect Auth in ECK Enables Namespace-Scoped Metadata SpoofingIncorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch client trust bundle managed by ECK in a separate namespace. |
|
| CVE-2026-63138 | Sep 01, 2026 |
Kibana NoSQLi Enables Unauthorized Data DisclosureImproper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read. |
|
| CVE-2026-78597 | Sep 01, 2026 |
Kibana Entity Store Missing Auth: Unauthorized API Key CreationMissing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and persists Elasticsearch API keys under the caller's identity, bypassing the elevated cluster and Kibana privileges that the documented Entity Store setup flow requires. |
|
| CVE-2026-78592 | Sep 01, 2026 |
Elastic's Kibana Path Traversal (CWE-22) Enables Unauthorized Resource DeletionImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management interface to act on an unintended target, resulting in the deletion of privileged resources including administrative accounts and other organizational assets. Exploitation requires an administrator to interact with the affected interface. |
|
| CVE-2026-78606 | Sep 01, 2026 |
Kibana Unauthorized Access to Elastic AI Assistant KB via ACL flawIncorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries. |
|
| CVE-2026-78603 | Sep 01, 2026 |
Kibana RBAC Bypass Enables Fleet Metadata DisclosureMissing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space. |
|
| CVE-2026-78607 | Sep 01, 2026 |
Elasticsearch Custom Inference Service Missing Auth => Info DisclosureMissing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause administrator-provisioned credentials to be exposed. |
|
| CVE-2026-78608 | Sep 01, 2026 |
Kibana Missing Auth Allows APM Credentials LeakMissing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any authenticated Kibana user to read APM server credentials that should be restricted to users holding APM or Fleet administrative privileges. |
|
| CVE-2026-78605 | Sep 01, 2026 |
Elasticsearch HTTP Request Smuggling: Info DisclosureInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users. |
|
| CVE-2026-72654 | Sep 01, 2026 |
Kibana ML Privilege Abuse (CWE-250)Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required. |
|
| CVE-2026-72633 | Sep 01, 2026 |
Kibana Entity Analytics Authorization Bypass Enables ACL SkipIncorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators. |
|
| CVE-2026-72641 | Sep 01, 2026 |
Kibana Unauthorized Mod via Entity Store Maintainer Tasks (CWE-863)Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space. |
|
| CVE-2026-72628 | Sep 01, 2026 |
Kibana DoS via CVE-2026-72628 Zip Bomb Memory ExhaustionImproper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted. |
|
| CVE-2026-72644 | Sep 01, 2026 |
Kibana DoS via Unhandled Exception in Observability AI AssistantUncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process and denying service to all users and spaces on that instance until it is restarted. |
|
| CVE-2026-72649 | Sep 01, 2026 |
Elasticsearch ML: Remote Code Exec via Untrusted Deserialized Trained ModelDeserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models. |
|
| CVE-2026-72682 | Sep 01, 2026 |
Kibana Unbounded Memory DoS via Low-Privilege Agent Builder (CWE-770)Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, terminating the process and denying service to all users of the instance. |
|
| CVE-2026-63137 | Sep 01, 2026 |
Kibana Privilege Escalation via Workflow Edit RBAC Bypass (CVE-2026-63137)Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope. |
|
| CVE-2026-72652 | Sep 01, 2026 |
Kibana AuthDoS via Unbounded Resource AllocationAllocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable. |
|
| CVE-2026-56143 | Sep 01, 2026 |
Elasticsearch Excessive Memory Allocation DoSAllocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable. |
|
| CVE-2026-33465 | Sep 01, 2026 |
Kibana Authenticated DoS via Unbounded Resource AllocationAllocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable. |
|
| CVE-2024-14047 | Sep 01, 2026 |
Winlogbeat Installer Escalation via Writable Dir (CVE-2024-14047)A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated Winlogbeat operation to write to or delete arbitrary files. Successful exploitation could result in a denial of service. |
|
| CVE-2026-78581 | Aug 25, 2026 |
Kibana Authorization Bypass via UserControlled KeyAuthorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier. |
|
| CVE-2026-49096 | Aug 13, 2026 |
Kibana Cases Uncaught Exception - Denial of Service via Malformed LinkUncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened it until the stored comment was removed. |
|
| CVE-2026-72636 | Aug 13, 2026 |
Elasticsearch Wildcard Matching Recursion Overflow Enables DoSUncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bound on recursion depth or on the total number of match operations performed. A search request containing a wildcard pattern with a large number of wildcard groups, evaluated against a sufficiently long name, exhausts the thread stack. Elasticsearch treats a stack overflow as an unrecoverable condition and shuts the node down, so the request terminates the affected node rather than failing gracefully. |
|
| CVE-2026-72632 | Aug 13, 2026 |
Kibana Fleet API Key Disclosure via Faulty Observable FilteringObservable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests. |
|
| CVE-2026-72631 | Aug 13, 2026 |
Kibana Fleet privilege escalation via API key injectionImproper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to Elastic Agents enrolled in the corresponding agent policy. The resulting key allows new documents to be inserted and index mappings to be extended for specific indices. The key does not allow reading, updating, or deleting existing documents |
|
| CVE-2026-72630 | Aug 13, 2026 |
Kibana Fleet Auth Mischeck Enables Privilege EscalationIncorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration recorded on the stored policy rather than against the replacement integration supplied with the update. An authenticated user holding only the Elastic Defend endpoint policy management privilege was therefore able to convert an endpoint policy they administer into a policy for a different integration, and to supply that integration's configuration at the same time. |
|
| CVE-2026-72629 | Aug 13, 2026 |
Kibana Auth Bypass (CWE-639) Exposes Model Inference OutputAuthorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the deployment stop and deployment update operations, allowing an active trained model deployment in another space to be stopped or to have its allocated resources altered. |
|
| CVE-2026-72643 | Aug 13, 2026 |
Kibana Agent Builder Owner Mismatch Enables Unauthorized Agent ChangesKibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in different realms are treated as the same owner. This discloses the configuration and instructions of an agent the caller does not own, and allows that agent to be altered or removed. |
|