Known vulnerabilities in Kibana

Software: Kibana
Software CPE: cpe:2.3:a:elastic_stack:kibana:*:*:*:*:*:*:*:*
Total vulnerabilities: 152
Public exploits: 5
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Kibana Kibana is affected by 152 known vulnerabilities: 2 critical, 8 high, 40 medium, 102 low Critical High Medium Low

Vulnerabilities (152)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU142360 - Relative Path Traversal
CVE-2026-72677
CWE-23 Low
No
No
8.19.17, 9.3.6, 9.4.3 13.08.2026 SB2026081369
#VU142351 - Allocation of Resources Without Limits or Throttling
CVE-2026-72651
CWE-770 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142350 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-72655
CWE-915 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142349 - Incorrect Authorization
CVE-2026-72673
CWE-863 Low
No
No
8.19.20, 9.4.4 13.08.2026 SB2026081368
#VU142348 - Inefficient Algorithmic Complexity
CVE-2026-72663
CWE-407 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142347 - Authorization Bypass Through User-Controlled Key
CVE-2026-72650
CWE-639 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142346 - Exposure of sensitive information to an unauthorized actor
CVE-2026-72670
CWE-200 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142345 - Missing Authorization
CVE-2026-72671
CWE-862 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142344 - Missing Authorization
CVE-2026-72675
CWE-862 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142343 - Missing Authorization
CVE-2026-72664
CWE-862 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142342 - Missing Authorization
CVE-2026-72665
CWE-862 Medium
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142341 - Allocation of Resources Without Limits or Throttling
CVE-2026-72667
CWE-770 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142340 - Cross-Site Request Forgery (CSRF)
CVE-2026-72658
CWE-352 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142339 - Allocation of Resources Without Limits or Throttling
CVE-2026-72674
CWE-770 Low
No
No
9.3.8, 9.4.4 13.08.2026 SB2026081368
#VU142338 - Missing Authorization
CVE-2026-72681
CWE-862 Low
No
No
9.4.4 13.08.2026 SB2026081368
#VU142337 - Incorrect Authorization
CVE-2026-72643
CWE-863 Low
No
No
9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142336 - Improper Privilege Management
CVE-2026-72631
CWE-269 Low
No
No
9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142335 - Authorization Bypass Through User-Controlled Key
CVE-2026-72680
CWE-639 Low
No
No
9.4.5 13.08.2026 SB2026081368
#VU142334 - Incorrect Authorization
CVE-2026-72672
CWE-863 Low
No
No
9.4.5 13.08.2026 SB2026081368
#VU142333 - Authorization Bypass Through User-Controlled Key
CVE-2026-72666
CWE-639 Low
No
No
9.4.5 13.08.2026 SB2026081368


Showing elements 1 - 20 out of 152