Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kibana MEDIUM 5.3
CVE-2026-33463

Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how exp…

Fix: 8.19.16 / 9.3.5+
Fix from $1,600 2026-05-28
Elastic Package Registry MEDIUM 5.9
CVE-2026-33467

Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffi…

Fix: 1.38.0+
Fix from $1,600 2026-04-28
Logstash CRITICAL 9.8
CVE-2026-33466

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code executi…

Fix: 8.19.14 / 9.2.8+
Fix from $2,300 2026-04-08
Kibana HIGH 7.7
CVE-2026-33458

Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and exe…

Fix: 9.3.3+
Fix from $1,950 2026-04-08
Kibana MEDIUM 6.5
CVE-2026-33459

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with …

Fix: 8.19.14 / 9.2.8+
Fix from $1,600 2026-04-08
Kibana HIGH 7.7
CVE-2026-4498

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elastic…

Fix: 8.19.14 / 9.2.8+
Fix from $1,950 2026-04-08
Kibana MEDIUM 6.5
CVE-2026-33461

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user with limited Fleet privileges …

Fix: 8.19.14 / 9.2.8+
Fix from $1,600 2026-04-08
Kibana MEDIUM 6.5
CVE-2026-26939

Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (ho…

Fix: 8.19.12 / 9.2.6+
Fix from $1,600 2026-03-19
Kibana MEDIUM 6.5
CVE-2026-26940

Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive…

Fix: 8.19.13 / 9.2.7+
Fix from $1,600 2026-03-19
Kibana HIGH 7.7
CVE-2026-26938

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read …

Mitigation only
Fix from $1,950 2026-02-26
Kibana HIGH 7.5
CVE-2026-26937

Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)

Fix: 8.19.11 / 9.2.5+
Fix from $1,950 2026-02-26
Kibana HIGH 7.5
CVE-2026-26935

Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulatio…

Fix: 8.19.12 / 9.2.6+
Fix from $1,950 2026-02-26
Kibana HIGH 7.5
CVE-2026-26936

Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expres…

Fix: 8.19.11 / 9.2.5+
Fix from $1,950 2026-02-26
Kibana MEDIUM 6.5
CVE-2026-26934

Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-only privileges to cause a Deni…

Fix: 8.19.12 / 9.2.6+
Fix from $1,600 2026-02-26
Kibana MEDIUM 6.5
CVE-2026-0543

Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially…

Fix: 8.19.0 / 9.1.10+
Fix from $1,600 2026-01-13
Kibana HIGH 7.5
CVE-2026-0528

Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation …

Fix: 7.17.29 / 8.19.10+
Fix from $1,950 2026-01-13
Kibana MEDIUM 6.5
CVE-2026-0530

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted r…

Fix: 7.17.29 / 8.19.10+
Fix from $1,600 2026-01-13
Kibana MEDIUM 6.5
CVE-2026-0531

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted b…

Fix: 7.17.29 / 8.19.10+
Fix from $1,600 2026-01-13
Kibana MEDIUM 6.5
CVE-2025-68389

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation …

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Kibana MEDIUM 6.1
CVE-2025-68385

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious scrip…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Kibana MEDIUM 6.1
CVE-2025-68387

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious scr…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Filebeat MEDIUM 6.5
CVE-2025-68383

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Elasticsearch MEDIUM 6.5
CVE-2025-68384

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allo…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Elasticsearch HIGH 7.4
CVE-2025-37731

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would …

Fix: 8.19.8 / 9.1.8+
Fix from $1,950 2025-12-15
Kibana MEDIUM 5.4
CVE-2025-37732

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within…

Fix: 8.19.8 / 9.1.8+
Fix from $1,600 2025-12-15
Elastic Cloud Enterprise HIGH 8.8
CVE-2025-37736

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be…

Fix: 3.8.3 / 4.0.3+
Fix from $1,950 2025-11-07
Elastic Cloud Enterprise HIGH 7.2
CVE-2025-37729

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin acce…

Fix: 3.8.2 / 4.0.2+
Fix from $1,950 2025-10-13
Elasticsearch MEDIUM 5.7
CVE-2025-37727

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing reques…

Fix: 8.18.8 / 8.19.5+
Fix from $1,600 2025-10-10
Kibana MEDIUM 5.4
CVE-2025-25018

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

Fix: 8.18.8 / 8.19.5+
Fix from $1,600 2025-10-10
Kibana MEDIUM 6.1
CVE-2025-25017

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

Fix: 8.18.8 / 8.19.4+
Fix from $1,600 2025-10-10