Kibana
This hub aggregates every CVE we track for Kibana, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
138
CVEs tracked
11
Critical
25
High
1
In CISA KEV
Severity distribution
MEDIUM99HIGH25CRITICAL11LOW3
Monthly trend
1
0
1
0
5
0
1
2
3
2
0
1
0
4
3
6
5
5
2
5
10
0
17
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Kibana.
- CVE-2026-63262Missing Authorization in Kibana Leading to Information Disclosure4.3
- CVE-2026-63261Uncontrolled Resource Consumption in Kibana Leading to Denial of Service6.5
- CVE-2026-63260Uncontrolled Resource Consumption in Kibana Leading to Denial of Service6.5
- CVE-2026-63259Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure4.3
- CVE-2026-63145Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise4.3
- CVE-2026-63143Missing Authorization in Kibana Leading to Unauthorized Information Disclosure4.3
- CVE-2026-63142Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery5.0
- CVE-2026-63141Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions6.3
- CVE-2026-63139Uncontrolled Resource Consumption in Kibana Leading to Denial of Service6.5
- CVE-2026-56147Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity Compromise7.1
- CVE-2026-56146Improper Access Control in Kibana Leading to Unauthorized Data Modification and Information Disclosure5.4
- CVE-2026-42397Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service6.5
- CVE-2026-49092Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information Exposure4.3
- CVE-2026-49091Improper Output Neutralization for Logs in Kibana Leading to Log Injection8.0
- CVE-2026-49088Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosure4.4
Product normalization is registry-driven with AI assist and human review. How it works