Known Vulnerabilities for Kibana by Elastic
Listed below are 10 of the newest known vulnerabilities associated with "Kibana" by "Elastic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63262 json | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-63261 json | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A l... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63260 json | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An ... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63259 json | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied ide... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63145 json | Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification recor... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63143 json | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A ... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63142 json | Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting fea... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63141 json | Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and s... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63139 json | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An ... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-56151 json | Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An auth... | Not Provided | 2026-07-01 | 2026-07-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elastic | Kibana | 7.9.2 | |||
| Application | Elastic | Kibana | 7.9.1 | |||
| Application | Elastic | Kibana | 7.9.0 | |||
| Application | Elastic | Kibana | 7.8.1 | |||
| Application | Elastic | Kibana | 7.8.0 | |||
| Application | Elastic | Kibana | 7.7.1 | |||
| Application | Elastic | Kibana | 7.7.0 | |||
| Application | Elastic | Kibana | 7.6.2 | |||
| Application | Elastic | Kibana | 7.6.1 | |||
| Application | Elastic | Kibana | 7.6.0 | |||
| Application | Elastic | Kibana | 7.5.2 | |||
| Application | Elastic | Kibana | 7.5.1 | |||
| Application | Elastic | Kibana | 7.5.0 | |||
| Application | Elastic | Kibana | 7.4.2 | |||
| Application | Elastic | Kibana | 7.4.1 | |||
| Application | Elastic | Kibana | 7.4.0 | |||
| Application | Elastic | Kibana | 7.3.2 | |||
| Application | Elastic | Kibana | 7.3.1 | |||
| Application | Elastic | Kibana | 7.3.0 | |||
| Application | Elastic | Kibana | 7.2.1 |