← Browse

Elastic

67 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-49089 MEDIUM 6.5 Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc… 2026-08-13 CVE-2026-49096 MEDIUM 4.3 Kibana — Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-… 2026-08-13 CVE-2026-72629 HIGH 7.1 Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space acce… 2026-08-13 CVE-2026-72630 HIGH 7.1 Kibana — Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-… 2026-08-13 CVE-2026-72631 MEDIUM 6.5 Kibana — Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalat… 2026-08-13 CVE-2026-72632 HIGH 7.1 Kibana — Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116)… 2026-08-13 CVE-2026-72636 MEDIUM 6.5 Elasticsearch — Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service… 2026-08-13 CVE-2026-72638 MEDIUM 6.5 Elasticsearch — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (C… 2026-08-13 CVE-2026-72639 MEDIUM 6.5 Elasticsearch — Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting optio… 2026-08-13 CVE-2026-72640 MEDIUM 6.5 Eck Operator — The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets… 2026-08-13 CVE-2026-72642 HIGH 8.8 Elasticsearch — The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a mo… 2026-08-13 CVE-2026-72643 HIGH 7.1 Kibana — Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier wh… 2026-08-13 CVE-2026-72645 MEDIUM 6.5 Elasticsearch — Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Exces… 2026-08-13 CVE-2026-72647 MEDIUM 6.5 Elasticsearch — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Neste… 2026-08-13 CVE-2026-72648 MEDIUM 6.5 Eck Operator — Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes… 2026-08-13 CVE-2026-72650 MEDIUM 4.3 Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Ac… 2026-08-13 CVE-2026-72651 MEDIUM 6.5 Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc… 2026-08-13 CVE-2026-72653 MEDIUM 6.5 Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc… 2026-08-13 CVE-2026-72655 MEDIUM 4.3 Kibana — Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case managemen… 2026-08-13 CVE-2026-72656 MEDIUM 6.5 Elasticsearch — Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead … 2026-08-13 CVE-2026-72657 MEDIUM 6.5 Fleet Server — Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure … 2026-08-13 CVE-2026-72658 HIGH 7.3 Kibana — Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery… 2026-08-13 CVE-2026-72659 MEDIUM 6.5 Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Exc… 2026-08-13 CVE-2026-72660 MEDIUM 6.5 Kibana — Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial … 2026-08-13 CVE-2026-72661 MEDIUM 6.5 Kibana — Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not P… 2026-08-13 CVE-2026-72663 MEDIUM 6.5 Kibana — Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulati… 2026-08-13 CVE-2026-72664 MEDIUM 6.5 Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response action… 2026-08-13 CVE-2026-72665 HIGH 8.1 Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend res… 2026-08-13 CVE-2026-72666 MEDIUM 6.8 Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution … 2026-08-13 CVE-2026-72667 MEDIUM 6.5 Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E… 2026-08-13 CVE-2026-72669 HIGH 7.6 Kibana — The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flo… 2026-08-13 CVE-2026-72670 HIGH 7.7 Kibana — A lower privileged user who holds only the privilege to read agent policies can read the entire configuration … 2026-08-13 CVE-2026-72671 MEDIUM 4.3 Kibana — A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learni… 2026-08-13 CVE-2026-72672 HIGH 7.7 Kibana — The Elastic Security capability that suggests existing field values while a user authors endpoint policy artif… 2026-08-13 CVE-2026-72673 MEDIUM 5.4 Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations … 2026-08-13 CVE-2026-72674 MEDIUM 6.5 Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E… 2026-08-13 CVE-2026-72675 HIGH 7.1 Kibana — Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data… 2026-08-13 CVE-2026-72676 MEDIUM 6.5 Fleet Server — Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution o… 2026-08-13 CVE-2026-72677 HIGH 7.3 Kibana — Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relat… 2026-08-13 CVE-2026-72678 MEDIUM 6.5 Elasticsearch — Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to res… 2026-08-13 CVE-2026-72679 MEDIUM 6.5 Elasticsearch — Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by … 2026-08-13 CVE-2026-72680 MEDIUM 6.5 Kibana — Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-sup… 2026-08-13 CVE-2026-72681 MEDIUM 6.5 Kibana — Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a sep… 2026-08-13 CVE-2026-72683 MEDIUM 6.5 Elasticsearch — A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipel… 2026-08-13 CVE-2026-72684 MEDIUM 6.5 Elasticsearch — A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search req… 2026-08-13 CVE-2026-72685 MEDIUM 4.3 Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single … 2026-08-13 CVE-2026-72686 MEDIUM 6.5 Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a cra… 2026-08-13 CVE-2026-72687 MEDIUM 6.5 Elasticsearch — A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing… 2026-08-13 CVE-2026-42397 MEDIUM 6.5 Kibana — Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E… 2026-07-21 CVE-2026-49092 MEDIUM 4.3 Kibana — Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information … 2026-07-21 CVE-2026-56144 MEDIUM 5.3 Elasticsearch — Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileg… 2026-07-21 CVE-2026-56145 MEDIUM 6.5 Elasticsearch — Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Alloc… 2026-07-21 CVE-2026-56146 MEDIUM 5.4 Kibana — Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlis… 2026-07-21 CVE-2026-56147 HIGH 7.1 Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disc… 2026-07-21 CVE-2026-63136 MEDIUM 6.5 Elasticsearch — Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Alloc… 2026-07-21 CVE-2026-63139 MEDIUM 6.5 Kibana — Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (… 2026-07-21 CVE-2026-63140 MEDIUM 6.5 Elasticsearch — Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPE… 2026-07-21 CVE-2026-63141 MEDIUM 6.3 Kibana — Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect conf… 2026-07-21 CVE-2026-63142 MEDIUM 5 Kibana — Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to th… 2026-07-21 CVE-2026-63143 MEDIUM 4.3 Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse … 2026-07-21 CVE-2026-63144 MEDIUM 6.5 Elasticsearch — Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search… 2026-07-21 CVE-2026-63145 MEDIUM 4.3 Kibana — Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and not… 2026-07-21 CVE-2026-63259 MEDIUM 4.3 Kibana — Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via us… 2026-07-21 CVE-2026-63260 MEDIUM 6.5 Kibana — Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (… 2026-07-21 CVE-2026-63261 MEDIUM 6.5 Kibana — Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (… 2026-07-21 CVE-2026-63262 MEDIUM 4.3 Kibana — Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user… 2026-07-21 CVE-2026-63263 MEDIUM 6.5 Elasticsearch — Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Dat… 2026-07-21