Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Elasticsearch MEDIUM 6.5
CVE-2026-63263

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticat…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-22
Elasticsearch MEDIUM 6.5
CVE-2026-63144

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged …

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Kibana MEDIUM 6.5
CVE-2026-63260

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker w…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Kibana MEDIUM 6.5
CVE-2026-63261

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authentica…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Kibana MEDIUM 5.0
CVE-2026-63142

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound …

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Kibana MEDIUM 5.4
CVE-2026-63141

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without …

Fix: 9.3.8 / 9.4.4+
Fix from $1,600 2026-07-21
Elasticsearch MEDIUM 6.5
CVE-2026-63140

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search requ…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Kibana HIGH 7.1
CVE-2026-56147

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity co…

Fix: 8.19.18 / 9.3.7+
Fix from $1,950 2026-07-21
Elasticsearch MEDIUM 6.5
CVE-2026-63136

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search p…

Fix: 8.19.15 / 9.2.9+
Fix from $1,600 2026-07-21
Kibana MEDIUM 6.5
CVE-2026-63139

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privil…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Elasticsearch MEDIUM 6.5
CVE-2026-56144

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorizatio…

Fix: 8.19.18 / 9.3.7+
Fix from $1,600 2026-07-21
Elasticsearch MEDIUM 6.5
CVE-2026-56145

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged aut…

Fix: 8.19.18 / 9.3.7+
Fix from $1,600 2026-07-21
Kibana MEDIUM 5.4
CVE-2026-56146

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential informati…

Fix: 9.4.3+
Fix from $1,600 2026-07-21
Kibana MEDIUM 6.5
CVE-2026-42397

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An aut…

Fix: 9.3.7 / 9.4.4+
Fix from $1,600 2026-07-21
Kibana HIGH 8.0
CVE-2026-49091

Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can…

Fix: 7.17.15 / 8.11.1+
Fix from $1,950 2026-07-01
Elasticsearch MEDIUM 6.5
CVE-2026-49090

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated u…

Fix: 7.17.24 / 8.15.0+
Fix from $1,600 2026-07-01
Fleet Server HIGH 7.5
CVE-2026-56150

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). …

Fix: 8.19.11 / 9.2.5+
Fix from $1,950 2026-07-01
Kibana MEDIUM 6.5
CVE-2026-56151

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submi…

Fix: 8.19.17 / 9.3.6+
Fix from $1,600 2026-07-01
Endpoint Security MEDIUM 5.3
CVE-2026-56152

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrai…

Fix: 8.19.13 / 9.2.7+
Fix from $1,600 2026-07-01
Elasticsearch MEDIUM 6.5
CVE-2026-56148

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can sub…

Fix: 8.19.17 / 9.3.6+
Fix from $1,600 2026-07-01
Kibana MEDIUM 6.5
CVE-2026-49087

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An aut…

Fix: 8.19.15 / 9.3.4+
Fix from $1,600 2026-07-01
Kibana HIGH 7.7
CVE-2026-49093

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configure…

Fix: 9.3.3+
Fix from $1,950 2026-05-28
Kibana MEDIUM 6.5
CVE-2026-49094

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with …

Fix: 8.19.16+
Fix from $1,600 2026-05-28
Kibana MEDIUM 6.5
CVE-2026-49095

Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with F…

Fix: 8.19.16 / 9.3.5+
Fix from $1,600 2026-05-28
Kibana HIGH 7.7
CVE-2026-42398

Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured con…

Fix: 9.2.8 / 9.3.2+
Fix from $1,950 2026-05-28
Kibana MEDIUM 6.5
CVE-2026-42399

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privil…

Fix: 8.19.16 / 9.3.5+
Fix from $1,600 2026-05-28
Kibana MEDIUM 6.5
CVE-2026-42400

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can s…

Fix: 8.19.16 / 9.3.5+
Fix from $1,600 2026-05-28
Kibana MEDIUM 6.5
CVE-2026-33464

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user hol…

Fix: 8.19.16 / 9.3.5+
Fix from $1,600 2026-05-28
Kibana MEDIUM 5.4
CVE-2026-42401

Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elas…

Fix: 8.19.16 / 9.3.5+
Fix from $1,600 2026-05-28
Kibana HIGH 7.3
CVE-2026-33462

A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could cr…

Fix: 8.19.16 / 9.3.5+
Fix from $1,950 2026-05-28