Elastic
67 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-49089
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc…
2026-08-13
CVE-2026-49096
MEDIUM 4.3
Kibana — Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-…
2026-08-13
CVE-2026-72629
HIGH 7.1
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space acce…
2026-08-13
CVE-2026-72630
HIGH 7.1
Kibana — Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-…
2026-08-13
CVE-2026-72631
MEDIUM 6.5
Kibana — Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalat…
2026-08-13
CVE-2026-72632
HIGH 7.1
Kibana — Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116)…
2026-08-13
CVE-2026-72636
MEDIUM 6.5
Elasticsearch — Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service…
2026-08-13
CVE-2026-72638
MEDIUM 6.5
Elasticsearch — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (C…
2026-08-13
CVE-2026-72639
MEDIUM 6.5
Elasticsearch — Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting optio…
2026-08-13
CVE-2026-72640
MEDIUM 6.5
Eck Operator — The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets…
2026-08-13
CVE-2026-72642
HIGH 8.8
Elasticsearch — The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a mo…
2026-08-13
CVE-2026-72643
HIGH 7.1
Kibana — Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier wh…
2026-08-13
CVE-2026-72645
MEDIUM 6.5
Elasticsearch — Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Exces…
2026-08-13
CVE-2026-72647
MEDIUM 6.5
Elasticsearch — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Neste…
2026-08-13
CVE-2026-72648
MEDIUM 6.5
Eck Operator — Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes…
2026-08-13
CVE-2026-72650
MEDIUM 4.3
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Ac…
2026-08-13
CVE-2026-72651
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc…
2026-08-13
CVE-2026-72653
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc…
2026-08-13
CVE-2026-72655
MEDIUM 4.3
Kibana — Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case managemen…
2026-08-13
CVE-2026-72656
MEDIUM 6.5
Elasticsearch — Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead …
2026-08-13
CVE-2026-72657
MEDIUM 6.5
Fleet Server — Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure …
2026-08-13
CVE-2026-72658
HIGH 7.3
Kibana — Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery…
2026-08-13
CVE-2026-72659
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc…
2026-08-13
CVE-2026-72660
MEDIUM 6.5
Kibana — Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial …
2026-08-13
CVE-2026-72661
MEDIUM 6.5
Kibana — Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not P…
2026-08-13
CVE-2026-72663
MEDIUM 6.5
Kibana — Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulati…
2026-08-13
CVE-2026-72664
MEDIUM 6.5
Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response action…
2026-08-13
CVE-2026-72665
HIGH 8.1
Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend res…
2026-08-13
CVE-2026-72666
MEDIUM 6.8
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution …
2026-08-13
CVE-2026-72667
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-08-13
CVE-2026-72669
HIGH 7.6
Kibana — The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flo…
2026-08-13
CVE-2026-72670
HIGH 7.7
Kibana — A lower privileged user who holds only the privilege to read agent policies can read the entire configuration …
2026-08-13
CVE-2026-72671
MEDIUM 4.3
Kibana — A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learni…
2026-08-13
CVE-2026-72672
HIGH 7.7
Kibana — The Elastic Security capability that suggests existing field values while a user authors endpoint policy artif…
2026-08-13
CVE-2026-72673
MEDIUM 5.4
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations …
2026-08-13
CVE-2026-72674
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-08-13
CVE-2026-72675
HIGH 7.1
Kibana — Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data…
2026-08-13
CVE-2026-72676
MEDIUM 6.5
Fleet Server — Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution o…
2026-08-13
CVE-2026-72677
HIGH 7.3
Kibana — Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relat…
2026-08-13
CVE-2026-72678
MEDIUM 6.5
Elasticsearch — Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to res…
2026-08-13
CVE-2026-72679
MEDIUM 6.5
Elasticsearch — Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by …
2026-08-13
CVE-2026-72680
MEDIUM 6.5
Kibana — Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-sup…
2026-08-13
CVE-2026-72681
MEDIUM 6.5
Kibana — Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a sep…
2026-08-13
CVE-2026-72683
MEDIUM 6.5
Elasticsearch — A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipel…
2026-08-13
CVE-2026-72684
MEDIUM 6.5
Elasticsearch — A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search req…
2026-08-13
CVE-2026-72685
MEDIUM 4.3
Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single …
2026-08-13
CVE-2026-72686
MEDIUM 6.5
Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a cra…
2026-08-13
CVE-2026-72687
MEDIUM 6.5
Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing…
2026-08-13
CVE-2026-42397
MEDIUM 6.5
Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…
2026-07-21
CVE-2026-49092
MEDIUM 4.3
Kibana — Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information …
2026-07-21
CVE-2026-56144
MEDIUM 5.3
Elasticsearch — Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileg…
2026-07-21
CVE-2026-56145
MEDIUM 6.5
Elasticsearch — Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Alloc…
2026-07-21
CVE-2026-56146
MEDIUM 5.4
Kibana — Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlis…
2026-07-21
CVE-2026-56147
HIGH 7.1
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disc…
2026-07-21
CVE-2026-63136
MEDIUM 6.5
Elasticsearch — Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Alloc…
2026-07-21
CVE-2026-63139
MEDIUM 6.5
Kibana — Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (…
2026-07-21
CVE-2026-63140
MEDIUM 6.5
Elasticsearch — Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPE…
2026-07-21
CVE-2026-63141
MEDIUM 6.3
Kibana — Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect conf…
2026-07-21
CVE-2026-63142
MEDIUM 5
Kibana — Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to th…
2026-07-21
CVE-2026-63143
MEDIUM 4.3
Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse …
2026-07-21
CVE-2026-63144
MEDIUM 6.5
Elasticsearch — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search…
2026-07-21
CVE-2026-63145
MEDIUM 4.3
Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and not…
2026-07-21
CVE-2026-63259
MEDIUM 4.3
Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via us…
2026-07-21
CVE-2026-63260
MEDIUM 6.5
Kibana — Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (…
2026-07-21
CVE-2026-63261
MEDIUM 6.5
Kibana — Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (…
2026-07-21
CVE-2026-63262
MEDIUM 4.3
Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user…
2026-07-21
CVE-2026-63263
MEDIUM 6.5
Elasticsearch — Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Dat…
2026-07-21