Elastic Kibana
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Elastic Kibana.
Known Exploited Elastic Kibana Vulnerabilities
The following Elastic Kibana vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Kibana Arbitrary Code Execution |
Kibana contain an arbitrary code execution flaw in the Timelion visualizer. CVE-2019-7609 Exploit Probability: 95.3% |
January 10, 2022 |
The vulnerability CVE-2019-7609: Kibana Arbitrary Code Execution is in the top 1% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 105 vulnerabilities in Elastic Kibana with an average score of 6.1 out of ten. Last year, in 2025 Kibana had 25 security vulnerabilities published. That is, 80 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.56
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 105 | 6.15 |
| 2025 | 25 | 6.71 |
| 2024 | 8 | 6.30 |
| 2023 | 11 | 7.01 |
| 2022 | 7 | 5.53 |
| 2021 | 5 | 4.25 |
| 2020 | 6 | 6.10 |
| 2019 | 5 | 8.30 |
| 2018 | 7 | 7.16 |
It may take a day or so for new Kibana vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Elastic Kibana Security Vulnerabilities
Kibana Unauthorized Config Mod via Incorrect Authorization (CWE-863)
CVE-2026-82302
8.1 - High
- September 03, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
AuthZ
Kibana Incorrect Auth (CWE-863) Enables Info Disclosure
CVE-2026-82299
6.5 - Medium
- September 03, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
AuthZ
Kibana Incorrect Authorization Leading to DoS via Misconfigured Access Control
CVE-2026-82298
4.3 - Medium
- September 03, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
AuthZ
Kibana Missing Auth: Unauthorized Data Mod via Space Migration
CVE-2026-78596
4.3 - Medium
- September 03, 2026
Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope.
AuthZ
Missing Auth in Kibana Fleet: Read-Only Agent Credentials Leak
CVE-2026-78595
4.3 - Medium
- September 03, 2026
Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and access diagnostic content belonging to agents enrolled in other Kibana spaces.
AuthZ
Kibana Cribl RCE via Insufficient Validation of Config Field
CVE-2026-78593
4.3 - Medium
- September 03, 2026
An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized Elasticsearch permissions.
Code Injection
CVE-2026-78583: Kibana Privilege Escalation via Unvalidated Agent Credentials
CVE-2026-78583
8.1 - High
- September 03, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.
AuthZ
Kibana ML Feature - Incorrect Auth. Enables Unauthorized Resource Consumption
CVE-2026-82293
4.3 - Medium
- September 02, 2026
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their authorization scope, consuming cluster resources they should not be able to reach.
AuthZ
Kibana Unbounded Memory Allocation Leads to DoS by Low-Priv Auth User
CVE-2026-78586
6.5 - Medium
- September 02, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.
Allocation of Resources Without Limits or Throttling
Kibana Osquery LiveQuery Disclosure via Identifier Existence
CVE-2026-78584
4.3 - Medium
- September 02, 2026
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
Observable Response Discrepancy
Kibana Fleet Path Traversal leads to unauthorized deletion
CVE-2026-78591
6.3 - Medium
- September 02, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a higher-privileged user in the Fleet administration interface to act on an unintended target, resulting in the deletion of resources including accounts with elevated privileges.
Directory traversal
Elastic Kibana Fleet Path Traversal Deletion Vulnerability
CVE-2026-78590
7.3 - High
- September 02, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged resources such as user accounts and other organizational assets. Exploitation requires an administrator to interact with the affected Fleet interface.
Directory traversal
Kibana Fleet Path Traversal Violation Leads to Deletion
CVE-2026-78599
6.5 - Medium
- September 02, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a subsequent administrative delete action to act on unintended internal resources. Exploitation requires an administrator to interact with the affected Fleet interface.
Directory traversal
Kibana ML Job Auth Escalation: CrossSpace Data Exposure
CVE-2026-78598
5.4 - Medium
- September 02, 2026
Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single Kibana space could cause a job's saved object to become accessible across all spaces in the Kibana instance, without holding access rights to those additional spaces.
AuthZ
Kibana Entity Store Auth Bypass Exposes Data
CVE-2026-78601
5.5 - Medium
- September 02, 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from Elasticsearch indices that user is not authorized to access. Derived entity data from those indices is then exposed through the entity store output.
AuthZ
Kibana NoSQLi Enables Unauthorized Data Disclosure
CVE-2026-63138
6.5 - Medium
- September 01, 2026
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.
Improper Neutralization of Special Elements in Data Query Logic
Kibana Entity Store Missing Auth: Unauthorized API Key Creation
CVE-2026-78597
4.3 - Medium
- September 01, 2026
Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only low-privilege Security feature access could invoke an administrative operation that creates and persists Elasticsearch API keys under the caller's identity, bypassing the elevated cluster and Kibana privileges that the documented Entity Store setup flow requires.
AuthZ
Elastic's Kibana Path Traversal (CWE-22) Enables Unauthorized Resource Deletion
CVE-2026-78592
7.3 - High
- September 01, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding tag creation privileges could cause a subsequent administrative action in the tag management interface to act on an unintended target, resulting in the deletion of privileged resources including administrative accounts and other organizational assets. Exploitation requires an administrator to interact with the affected interface.
Directory traversal
Kibana Unauthorized Access to Elastic AI Assistant KB via ACL flaw
CVE-2026-78606
4.2 - Medium
- September 01, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.
AuthZ
Kibana RBAC Bypass Enables Fleet Metadata Disclosure
CVE-2026-78603
4.3 - Medium
- September 01, 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.
AuthZ
Kibana Missing Auth Allows APM Credentials Leak
CVE-2026-78608
6.5 - Medium
- September 01, 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any authenticated Kibana user to read APM server credentials that should be restricted to users holding APM or Fleet administrative privileges.
AuthZ
Kibana ML Privilege Abuse (CWE-250)
CVE-2026-72654
6.5 - Medium
- September 01, 2026
Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.
Execution with Unnecessary Privileges
Kibana Entity Analytics Authorization Bypass Enables ACL Skip
CVE-2026-72633
4.3 - Medium
- September 01, 2026
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.
AuthZ
Kibana Unauthorized Mod via Entity Store Maintainer Tasks (CWE-863)
CVE-2026-72641
5.4 - Medium
- September 01, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Security Solution read access in a Kibana space could enumerate and change the state of Entity Store maintainer tasks, silently disabling Entity Analytics maintenance for that space.
AuthZ
Kibana DoS via CVE-2026-72628 Zip Bomb Memory Exhaustion
CVE-2026-72628
6.5 - Medium
- September 01, 2026
Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted.
Data Amplification
Kibana DoS via Unhandled Exception in Observability AI Assistant
CVE-2026-72644
6.5 - Medium
- September 01, 2026
Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process and denying service to all users and spaces on that instance until it is restarted.
Uncaught Exception
Kibana Unbounded Memory DoS via Low-Privilege Agent Builder (CWE-770)
CVE-2026-72682
6.5 - Medium
- September 01, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, terminating the process and denying service to all users of the instance.
Allocation of Resources Without Limits or Throttling
Kibana Privilege Escalation via Workflow Edit RBAC Bypass (CVE-2026-63137)
CVE-2026-63137
8.3 - High
- September 01, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.
AuthZ
Kibana AuthDoS via Unbounded Resource Allocation
CVE-2026-72652
6.5 - Medium
- September 01, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.
Allocation of Resources Without Limits or Throttling
Kibana Authenticated DoS via Unbounded Resource Allocation
CVE-2026-33465
6.5 - Medium
- September 01, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.
Allocation of Resources Without Limits or Throttling
Kibana Authorization Bypass via UserControlled Key
CVE-2026-78581
4.2 - Medium
- August 25, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier.
Insecure Direct Object Reference / IDOR
Kibana Cases Uncaught Exception - Denial of Service via Malformed Link
CVE-2026-49096
4.3 - Medium
- August 13, 2026
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened it until the stored comment was removed.
Uncaught Exception
Kibana Fleet API Key Disclosure via Faulty Observable Filtering
CVE-2026-72632
7.1 - High
- August 13, 2026
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests.
Side Channel Attack
Kibana Fleet privilege escalation via API key injection
CVE-2026-72631
6.5 - Medium
- August 13, 2026
Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to Elastic Agents enrolled in the corresponding agent policy. The resulting key allows new documents to be inserted and index mappings to be extended for specific indices. The key does not allow reading, updating, or deleting existing documents
Improper Privilege Management
Kibana Fleet Auth Mischeck Enables Privilege Escalation
CVE-2026-72630
7.1 - High
- August 13, 2026
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration recorded on the stored policy rather than against the replacement integration supplied with the update. An authenticated user holding only the Elastic Defend endpoint policy management privilege was therefore able to convert an endpoint policy they administer into a policy for a different integration, and to supply that integration's configuration at the same time.
AuthZ
Kibana Auth Bypass (CWE-639) Exposes Model Inference Output
CVE-2026-72629
7.1 - High
- August 13, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the deployment stop and deployment update operations, allowing an active trained model deployment in another space to be stopped or to have its allocated resources altered.
Insecure Direct Object Reference / IDOR
Kibana Agent Builder Owner Mismatch Enables Unauthorized Agent Changes
CVE-2026-72643
7.1 - High
- August 13, 2026
Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in different realms are treated as the same owner. This discloses the configuration and instructions of an agent the caller does not own, and allows that agent to be altered or removed.
AuthZ
Unauthorized case data edit in Elastic Security Kibana (CVE-2026-72655)
CVE-2026-72655
4.3 - Medium
- August 13, 2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges, via Manipulating User-Controlled Variables (CAPEC-77). Object attributes accepted by the case management API were not subject to the same authorization enforcement applied in the user interface, so a low-privileged user could alter case records they were only entitled to view.
Mass Assignment
Kibana Resource Exhaustion DoS via Malformed Maintenance Window Payload
CVE-2026-72653
6.5 - Medium
- August 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. Kibana becomes unresponsive for all users and does not recover without manual intervention.
Allocation of Resources Without Limits or Throttling
Kibana Authenticated Read-Only User Causes DOS via Resource Exhaustion
CVE-2026-72651
6.5 - Medium
- August 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted.
Allocation of Resources Without Limits or Throttling
Kibana Auth Bypass via User-Key Exposes Cross-Space Telemetry
CVE-2026-72650
4.3 - Medium
- August 13, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve alerting rule execution telemetry that belongs to spaces the user is not authorized to access. The disclosed telemetry includes rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters.
Insecure Direct Object Reference / IDOR
Kibana TSVB DoS via Input Data Manipulation (CWE-407)
CVE-2026-72663
6.5 - Medium
- August 13, 2026
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the input. Because the evaluation runs synchronously, a single request consumes the Kibana request-processing thread indefinitely, and Kibana stops responding to all further requests until the service is restarted.
Inefficient Algorithmic Complexity
Kibana CVE-2026-72661: Missing Auth Enables Data Disclosure via Unconstrained ACLs
CVE-2026-72661
6.5 - Medium
- August 13, 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its user-facing equivalents require, and it retrieved data with elevated internal permissions rather than the permissions of the requesting user. As a result, an authenticated low-privileged Kibana user with no Security Solution privileges, endpoint privileges and no Elasticsearch privileges on the underlying data, could read endpoint response action records and the corresponding response content returned by managed hosts.
AuthZ
Kibana Uncaught Exception DoS via Improper Input Validation
CVE-2026-72660
6.5 - Medium
- August 13, 2026
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting error is raised on an execution path so it propagates as an uncaught exception and terminates the Kibana process. Kibana is unavailable to all users until the service is restarted, and the condition can be triggered repeatedly.
Uncaught Exception
Kibana: Unbounded Memory Allocation via Malformed Visualization Payload (CWE-770)
CVE-2026-72659
6.5 - Medium
- August 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged access is not correctly validated before use. Processing the request causes unbounded memory growth in the Kibana process, which is terminated by the host once available memory is exhausted. Kibana then becomes unavailable to all users until the service is restarted.
Allocation of Resources Without Limits or Throttling
Privilege Escalation via XSRF in Kibana Vega Visualizations
CVE-2026-72658
7.3 - High
- August 13, 2026
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.
Session Riding
DoS via Unbounded Resource Allocation in Kibana Validation
CVE-2026-72667
6.5 - Medium
- August 13, 2026
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capability of the Observability log analysis feature causes Kibana to perform an unbounded amount of concurrent work. This can exhaust the memory available to the Kibana process and make Kibana unavailable to all users until it is restarted. The severity of the outcome depends on the resources allocated to the deployment; on well-provisioned deployments a single request may cause degraded performance and elevated memory pressure rather than a full outage, but the request is inexpensive to repeat.
Allocation of Resources Without Limits or Throttling
Kibana Auth Bypass via User-Key (CWE-639) enabling CrossSpace Host Query
CVE-2026-72666
6.8 - Medium
- August 13, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery live queries in one space can have a query carried out on hosts belonging to another space, resulting in disclosure of information from those hosts to the Osquery results data stream.
Insecure Direct Object Reference / IDOR
Missing Authorization in Kibana Enables Unauthorized Osquery Exec
CVE-2026-72665
8.1 - High
- August 13, 2026
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.
AuthZ
Kibana CALE Unauthorized Exec of Elastic Defend Actions
CVE-2026-72664
6.5 - Medium
- August 13, 2026
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate automated endpoint response actions with a detection rule, even though the dedicated Endpoint response action privileges that govern those capabilities (host isolation, process operations, and execute operations) have not been granted to that user. When such a rule generates alerts, the associated response actions are carried out against the matching hosts.
AuthZ
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Elastic Kibana or by Elastic? Click the Watch button to subscribe.