Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47882
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72680 | MEDIUM | 6.5 | Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier … | Aug 13, 2026 |
| CVE-2026-72679 | MEDIUM | 6.5 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded … | Aug 13, 2026 |
| CVE-2026-72678 | MEDIUM | 6.5 | Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. … | Aug 13, 2026 |
| CVE-2026-72677 | HIGH | 7.3 | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied … | Aug 13, 2026 |
| CVE-2026-72676 | MEDIUM | 6.5 | Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). … | Aug 13, 2026 |
| CVE-2026-72675 | HIGH | 7.1 | Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its … | Aug 13, 2026 |
| CVE-2026-72674 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of … | Aug 13, 2026 |
| CVE-2026-72673 | MEDIUM | 5.4 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private … | Aug 13, 2026 |
| CVE-2026-72672 | HIGH | 7.7 | The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch … | Aug 13, 2026 |
| CVE-2026-72671 | MEDIUM | 4.3 | A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies … | Aug 13, 2026 |
| CVE-2026-72670 | HIGH | 7.7 | A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would … | Aug 13, 2026 |
| CVE-2026-72669 | HIGH | 7.6 | The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read … | Aug 13, 2026 |
| CVE-2026-72667 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request … | Aug 13, 2026 |
| CVE-2026-72666 | MEDIUM | 6.8 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the … | Aug 13, 2026 |
| CVE-2026-72665 | HIGH | 8.1 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly … | Aug 13, 2026 |
| CVE-2026-72664 | MEDIUM | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by … | Aug 13, 2026 |
| CVE-2026-72663 | MEDIUM | 6.5 | Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to … | Aug 13, 2026 |
| CVE-2026-72661 | MEDIUM | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability … | Aug 13, 2026 |
| CVE-2026-72660 | MEDIUM | 6.5 | Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user … | Aug 13, 2026 |
| CVE-2026-72659 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload … | Aug 13, 2026 |
| CVE-2026-72658 | HIGH | 7.3 | Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations … | Aug 13, 2026 |
| CVE-2026-72657 | MEDIUM | 6.5 | Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads … | Aug 13, 2026 |
| CVE-2026-72656 | MEDIUM | 6.5 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An … | Aug 13, 2026 |
| CVE-2026-72655 | MEDIUM | 4.3 | Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case … | Aug 13, 2026 |
| CVE-2026-72653 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is … | Aug 13, 2026 |