Kibana
This hub aggregates every CVE we track for Kibana, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
201
CVEs tracked
11
Critical
41
High
1
In CISA KEV
Severity distribution
MEDIUM146HIGH41CRITICAL11LOW3
Monthly trend
0
1
0
5
0
1
2
3
2
0
1
0
4
3
6
5
5
2
5
10
0
18
32
30
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Kibana.
- CVE-2026-82302Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification8.1
- CVE-2026-82299Incorrect Authorization in Kibana Leading to Information Disclosure6.5
- CVE-2026-82298Incorrect Authorization in Kibana Leading to Denial of Service4.3
- CVE-2026-78596Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations4.3
- CVE-2026-78595Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure4.3
- CVE-2026-78593Improper Control of Generation of Code in Kibana Leading to Privilege Escalation4.3
- CVE-2026-78583Incorrect Authorization in Kibana Leading to Privilege Escalation8.1
- CVE-2026-82293Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption4.3
- CVE-2026-78586Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service6.5
- CVE-2026-78584Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure4.3
- CVE-2026-78591Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource Deletion6.3
- CVE-2026-78590Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged Resources7.3
- CVE-2026-78599Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources6.5
- CVE-2026-78598Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine Learning Job Data5.4
- CVE-2026-78601Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure5.5
Product normalization is registry-driven with AI assist and human review. How it works