Elastic
90 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-78583
HIGH 8.1
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPE…
2026-09-03
CVE-2026-78593
MEDIUM 4.3
Kibana — An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user hol…
2026-09-03
CVE-2026-78595
MEDIUM 4.3
Kibana — Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kib…
2026-09-03
CVE-2026-78596
MEDIUM 4.3
Kibana — Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862)…
2026-09-03
CVE-2026-82298
MEDIUM 4.3
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configure…
2026-09-03
CVE-2026-82299
MEDIUM 6.5
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Conf…
2026-09-03
CVE-2026-82302
HIGH 8.1
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting…
2026-09-03
CVE-2026-78584
MEDIUM 4.3
Kibana — Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via…
2026-09-02
CVE-2026-78586
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-09-02
CVE-2026-78587
LOW 3.1
Fleet Server — Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations v…
2026-09-02
CVE-2026-78588
MEDIUM 6.5
Filebeat — Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via…
2026-09-02
CVE-2026-78590
HIGH 7.3
Kibana — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe…
2026-09-02
CVE-2026-78591
MEDIUM 6.3
Kibana — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe…
2026-09-02
CVE-2026-78594
MEDIUM 4.9
Apm Server — Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service…
2026-09-02
CVE-2026-78598
MEDIUM 5.4
Kibana — Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure vi…
2026-09-02
CVE-2026-78599
MEDIUM 6.5
Kibana — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe…
2026-09-02
CVE-2026-78600
LOW 3.5
Eck Operator — Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privileg…
2026-09-02
CVE-2026-78601
MEDIUM 5.5
Kibana — Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). …
2026-09-02
CVE-2026-78602
MEDIUM 5.3
Elastic Maps Server — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server…
2026-09-02
CVE-2026-78604
HIGH 7.8
Elastic Agent — Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege e…
2026-09-02
CVE-2026-78609
MEDIUM 5.4
Eck Operator — Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification o…
2026-09-02
CVE-2026-82293
MEDIUM 4.3
Kibana — Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource con…
2026-09-02
CVE-2026-33465
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-09-01
CVE-2026-56143
MEDIUM 4.9
Elasticsearch — Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of servic…
2026-09-01
CVE-2026-63137
HIGH 8.3
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Config…
2026-09-01
CVE-2026-63138
MEDIUM 6.5
Kibana — Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information di…
2026-09-01
CVE-2026-72628
MEDIUM 6.5
Kibana — Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive …
2026-09-01
CVE-2026-72633
MEDIUM 4.3
Kibana — Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Acc…
2026-09-01
CVE-2026-72641
MEDIUM 5.4
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functi…
2026-09-01
CVE-2026-72644
MEDIUM 6.5
Kibana — Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153)…
2026-09-01
CVE-2026-72649
HIGH 8.8
Elasticsearch — Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote…
2026-09-01
CVE-2026-72652
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-09-01
CVE-2026-72654
MEDIUM 6.5
Kibana — Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information…
2026-09-01
CVE-2026-72682
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-09-01
CVE-2026-78592
HIGH 7.3
Kibana — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Kibana can lead to …
2026-09-01
CVE-2026-78597
MEDIUM 4.3
Kibana — Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creatio…
2026-09-01
CVE-2026-78603
MEDIUM 4.3
Kibana — Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Config…
2026-09-01
CVE-2026-78605
MEDIUM 5.9
Elasticsearch — Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to…
2026-09-01
CVE-2026-78606
MEDIUM 4.2
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of…
2026-09-01
CVE-2026-78607
MEDIUM 5.4
Elasticsearch — Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosu…
2026-09-01
CVE-2026-78608
MEDIUM 6.5
Kibana — Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). …
2026-09-01
CVE-2026-78581
MEDIUM 4.2
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modificatio…
2026-08-25
CVE-2026-49089
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc…
2026-08-13
CVE-2026-49096
MEDIUM 4.3
Kibana — Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-…
2026-08-13
CVE-2026-72629
HIGH 7.1
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space acce…
2026-08-13
CVE-2026-72630
HIGH 7.1
Kibana — Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-…
2026-08-13
CVE-2026-72631
MEDIUM 6.5
Kibana — Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalat…
2026-08-13
CVE-2026-72632
HIGH 7.1
Kibana — Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116)…
2026-08-13
CVE-2026-72636
MEDIUM 6.5
Elasticsearch — Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service…
2026-08-13
CVE-2026-72638
MEDIUM 6.5
Elasticsearch — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (C…
2026-08-13
CVE-2026-72639
MEDIUM 6.5
Elasticsearch — Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting optio…
2026-08-13
CVE-2026-72640
MEDIUM 6.5
Eck Operator — The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets…
2026-08-13
CVE-2026-72642
HIGH 8.8
Elasticsearch — The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a mo…
2026-08-13
CVE-2026-72643
HIGH 7.1
Kibana — Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier wh…
2026-08-13
CVE-2026-72645
MEDIUM 6.5
Elasticsearch — Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Exces…
2026-08-13
CVE-2026-72647
MEDIUM 6.5
Elasticsearch — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Neste…
2026-08-13
CVE-2026-72648
MEDIUM 6.5
Eck Operator — Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes…
2026-08-13
CVE-2026-72650
MEDIUM 4.3
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Ac…
2026-08-13
CVE-2026-72651
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc…
2026-08-13
CVE-2026-72653
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc…
2026-08-13
CVE-2026-72655
MEDIUM 4.3
Kibana — Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case managemen…
2026-08-13
CVE-2026-72656
MEDIUM 6.5
Elasticsearch — Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead …
2026-08-13
CVE-2026-72657
MEDIUM 6.5
Fleet Server — Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure …
2026-08-13
CVE-2026-72658
HIGH 7.3
Kibana — Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery…
2026-08-13
CVE-2026-72659
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc…
2026-08-13
CVE-2026-72660
MEDIUM 6.5
Kibana — Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial …
2026-08-13
CVE-2026-72661
MEDIUM 6.5
Kibana — Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not P…
2026-08-13
CVE-2026-72663
MEDIUM 6.5
Kibana — Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulati…
2026-08-13
CVE-2026-72664
MEDIUM 6.5
Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response action…
2026-08-13
CVE-2026-72665
HIGH 8.1
Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend res…
2026-08-13
CVE-2026-72666
MEDIUM 6.8
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution …
2026-08-13
CVE-2026-72667
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-08-13
CVE-2026-72669
HIGH 7.6
Kibana — The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flo…
2026-08-13
CVE-2026-72670
HIGH 7.7
Kibana — A lower privileged user who holds only the privilege to read agent policies can read the entire configuration …
2026-08-13
CVE-2026-72671
MEDIUM 4.3
Kibana — A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learni…
2026-08-13
CVE-2026-72672
HIGH 7.7
Kibana — The Elastic Security capability that suggests existing field values while a user authors endpoint policy artif…
2026-08-13
CVE-2026-72673
MEDIUM 5.4
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations …
2026-08-13
CVE-2026-72674
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-08-13
CVE-2026-72675
HIGH 7.1
Kibana — Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data…
2026-08-13
CVE-2026-72676
MEDIUM 6.5
Fleet Server — Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution o…
2026-08-13
CVE-2026-72677
HIGH 7.3
Kibana — Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relat…
2026-08-13
CVE-2026-72678
MEDIUM 6.5
Elasticsearch — Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to res…
2026-08-13
CVE-2026-72679
MEDIUM 6.5
Elasticsearch — Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by …
2026-08-13
CVE-2026-72680
MEDIUM 6.5
Kibana — Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-sup…
2026-08-13
CVE-2026-72681
MEDIUM 6.5
Kibana — Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a sep…
2026-08-13
CVE-2026-72683
MEDIUM 6.5
Elasticsearch — A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipel…
2026-08-13
CVE-2026-72684
MEDIUM 6.5
Elasticsearch — A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search req…
2026-08-13
CVE-2026-72685
MEDIUM 4.3
Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single …
2026-08-13
CVE-2026-72686
MEDIUM 6.5
Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a cra…
2026-08-13
CVE-2026-72687
MEDIUM 6.5
Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing…
2026-08-13