Known vulnerabilities in Kibana 9.4.4

Software: Kibana
Version: 9.4.4
Software CPE: cpe:2.3:a:elastic_stack:kibana:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Kibana version 9.4.4 Kibana 9.4.4 is affected by 23 vulnerabilities: 2 medium, 21 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU142361 - Resource exhaustion
CWE-400 Medium
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142357 - Missing Authorization
CVE-2026-72669
CWE-862 Low
No
No
8.19.19, 9.4.5 13.08.2026 SB2026081368
#VU142356 - Uncaught Exception
CVE-2026-72660
CWE-248 Low
No
No
8.19.20, 9.3.8, 9.4.5 13.08.2026 SB2026081368
#VU142355 - Authorization Bypass Through User-Controlled Key
CVE-2026-72629
CWE-639 Low
No
No
8.19.20, 9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142354 - Incorrect Authorization
CVE-2026-72630
CWE-863 Low
No
No
8.19.20, 9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142353 - Observable discrepancy
CVE-2026-72632
CWE-203 Low
No
No
8.19.20, 9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142352 - Allocation of Resources Without Limits or Throttling
CVE-2026-72659
CWE-770 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142351 - Allocation of Resources Without Limits or Throttling
CVE-2026-72651
CWE-770 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142350 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-72655
CWE-915 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142348 - Inefficient Algorithmic Complexity
CVE-2026-72663
CWE-407 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142347 - Authorization Bypass Through User-Controlled Key
CVE-2026-72650
CWE-639 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142346 - Exposure of sensitive information to an unauthorized actor
CVE-2026-72670
CWE-200 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142345 - Missing Authorization
CVE-2026-72671
CWE-862 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142344 - Missing Authorization
CVE-2026-72675
CWE-862 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142343 - Missing Authorization
CVE-2026-72664
CWE-862 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142342 - Missing Authorization
CVE-2026-72665
CWE-862 Medium
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142341 - Allocation of Resources Without Limits or Throttling
CVE-2026-72667
CWE-770 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142340 - Cross-Site Request Forgery (CSRF)
CVE-2026-72658
CWE-352 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142337 - Incorrect Authorization
CVE-2026-72643
CWE-863 Low
No
No
9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142333 - Authorization Bypass Through User-Controlled Key
CVE-2026-72666
CWE-639 Low
No
No
9.4.5 13.08.2026 SB2026081368


Showing elements 1 - 20 out of 23