Known vulnerabilities in Kibana 8.19.19
Vendor:
Elastic Stack
Software:
Kibana
Version:
8.19.19
Software CPE:
cpe:2.3:a:elastic_stack:kibana:*:*:*:*:*:*:*:*
Website:
https://www.elastic.co/
Total vulnerabilities:
18
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Vulnerabilities by Severity
9.5.2
9.5.1
9.4.5
8.19.20
9.5.0
9.4.4
9.3.8
8.19.19
9.4.3
9.3.7
8.19.18
9.3.6
8.19.17
9.4.2
8.19.16
9.3.5
9.4.1
9.4.0
8.19.15
9.3.4
9.2.8
8.19.14
9.3.3
9.3.2
9.2.7
8.19.13
9.3.1
9.2.6
8.19.12
9.3.0
9.2.5
8.19.11
9.2.4
9.1.10
8.19.10
9.2.3
9.1.9
8.19.9
9.2.2
9.1.8
8.19.8
8.19.7
9.2.1
9.1.7
9.2.0
9.1.6
8.19.6
9.1.5
9.0.8
8.19.5
8.18.8
9.1.4
8.19.4
9.0.7
8.18.7
8.19.3
8.18.6
9.1.3
9.0.6
9.1.2
8.19.2
8.17.10
9.0.5
8.18.5
9.1.1
8.19.1
9.1.0
8.19.0
9.0.4
8.18.4
8.17.9
9.0.3
8.18.3
8.17.8
7.17.29
9.0.2
8.17.7
8.18.2
9.0.1
8.18.1
8.17.6
8.17.5
9.0.0
8.18.0
8.17.4
8.16.6
8.17.3
8.16.5
7.17.28
8.16.4
8.17.2
8.17.1
8.16.3
7.17.27
8.16.2
8.17.0
7.17.26
8.15.5
8.16.1
8.16.0
8.15.4
7.17.25
8.15.3
8.15.2
7.17.24
8.15.1
8.15.0
7.17.23
8.14.3
8.14.2
7.17.22
8.14.1
8.14.0
8.13.4
8.13.3
7.17.21
7.17.20
8.13.2
8.13.1
8.13.0
7.17.19
8.12.2
8.12.1
7.17.18
7.17.17
8.12.0
8.11.4
8.11.3
7.17.16
8.11.2
8.11.1
7.17.15
8.11.0
8.10.4
8.10.3
7.17.14
8.10.2
8.10.1
8.10.0
8.9.2
7.17.13
8.9.1
8.9.0
7.17.12
8.8.2
7.17.11
8.8.1
8.8.0
8.7.1
7.17.10
8.7.0
8.6.2
7.17.9
8.6.1
8.6.0
8.5.3
7.17.8
8.5.2
8.5.1
8.5.0
7.17.7
8.4.3
8.4.2
8.4.1
8.4.0
7.17.6
8.3.3
8.3.2
8.3.1
8.3.0
7.17.5
8.2.3
8.2.2
8.2.1
7.17.4
8.2.0
8.1.3
7.17.3
8.1.2
7.17.2
8.1.1
7.3.6
7.3.5
7.3.4
7.3.3
8.1.0
8.0.1
7.17.1
8.0.0
7.17.0
7.16.3
6.8.23
7.16.2
6.8.22
7.16.1
6.8.21
7.16.0
7.15.2
7.15.1
6.8.20
7.15.0
6.8.19
7.14.2
7.14.1
6.8.18
7.14.0
7.13.4
6.8.17
7.13.3
7.13.2
7.13.1
6.8.16
7.13.0
7.12.1
7.12.0
6.8.15
7.11.2
7.11.1
6.8.14
7.11.0
7.10.2
7.10.1
7.10.0
7.9.3
6.8.13
7.9.2
7.9.1
6.8.12
7.9.0
6.8.11
7.8.1
7.8.0
6.8.10
7.7.1
6.8.9
7.7.0
6.8.8
7.6.2
6.8.7
7.6.1
7.6.0
7.5.2
7.5.1
6.8.6
7.5.0
6.8.5
7.4.2
6.8.4
7.4.1
7.4.0
7.3.2
6.8.3
7.3.1
7.3.0
7.2.1
7.2.0
7.1.1
7.1.0
7.0.1
7.0.0
6.8.2
6.8.1
6.8.0
6.7.2
6.7.1
4.3.0
4.2.2
4.2.1
4.2.0
4.1.11
4.1.10
4.1.9
4.1.8
4.1.7
4.1.6
4.1.5
4.1.4
4.1.3
4.1.2
4.1.1
4.1.0
4.0.3
4.0.2
4.0.1
4.0.0
3.1.3
3.1.2
3.1.1
3.1.0
3.0.1
3.0.0
6.7.0
6.6.2
6.6.1
6.6.0
6.5.4
5.6.16
5.6.15
4.6.6
4.6.5
4.6.4
4.6.3
4.6.2
4.6.1
4.6.0
4.5.4
4.5.3
4.5.2
4.5.1
4.5.0
4.4.2
4.4.1
4.4.0
4.3.3
4.3.2
4.3.1
4.6
4.5
4.4
4.3
4.2
4.1
4.0
5.0.0
5.0.1
5.0.2
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.5.2
5.5.3
5.6.7
5.6.8
5.6.9
5.6.10
5.6.11
5.6.12
5.6.13
5.6.14
6.5.3
6.5.2
6.5.1
6.5.0
6.4.3
6.4.2
6.4.1
6.4.0
6.3.2
6.3.1
6.3.0
6.2.4
6.2.3
6.2.2
6.2.1
6.2.0
6.1.4
6.1.3
6.0.1
6.1.2
5.6.6
6.1.1
6.1.0
6.0.0
5.6.5
5.6.4
5.6.3
5.6.2
5.6.1
5.6.0
Vulnerabilities (18)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU142361 - Resource exhaustion |
CWE-400 | Medium | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142356 - Uncaught Exception CVE-2026-72660 |
CWE-248 | Low | 8.19.20, 9.3.8, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142355 - Authorization Bypass Through User-Controlled Key CVE-2026-72629 |
CWE-639 | Low | 8.19.20, 9.4.5, 9.5.1 | 13.08.2026 |
SB2026081368 |
||
| #VU142354 - Incorrect Authorization CVE-2026-72630 |
CWE-863 | Low | 8.19.20, 9.4.5, 9.5.1 | 13.08.2026 |
SB2026081368 |
||
| #VU142353 - Observable discrepancy CVE-2026-72632 |
CWE-203 | Low | 8.19.20, 9.4.5, 9.5.1 | 13.08.2026 |
SB2026081368 |
||
| #VU142352 - Allocation of Resources Without Limits or Throttling CVE-2026-72659 |
CWE-770 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142351 - Allocation of Resources Without Limits or Throttling CVE-2026-72651 |
CWE-770 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142350 - Improperly Controlled Modification of Dynamically-Determined Object Attributes CVE-2026-72655 |
CWE-915 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142349 - Incorrect Authorization CVE-2026-72673 |
CWE-863 | Low | 8.19.20, 9.4.4 | 13.08.2026 |
SB2026081368 |
||
| #VU142348 - Inefficient Algorithmic Complexity CVE-2026-72663 |
CWE-407 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142347 - Authorization Bypass Through User-Controlled Key CVE-2026-72650 |
CWE-639 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142346 - Exposure of sensitive information to an unauthorized actor CVE-2026-72670 |
CWE-200 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142345 - Missing Authorization CVE-2026-72671 |
CWE-862 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142344 - Missing Authorization CVE-2026-72675 |
CWE-862 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142343 - Missing Authorization CVE-2026-72664 |
CWE-862 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142342 - Missing Authorization CVE-2026-72665 |
CWE-862 | Medium | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142341 - Allocation of Resources Without Limits or Throttling CVE-2026-72667 |
CWE-770 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |
||
| #VU142340 - Cross-Site Request Forgery (CSRF) CVE-2026-72658 |
CWE-352 | Low | 8.19.20, 9.4.5 | 13.08.2026 |
SB2026081368 |