Known vulnerabilities in Kibana - page 2

Software: Kibana
Software CPE: cpe:2.3:a:elastic_stack:kibana:*:*:*:*:*:*:*:*
Total vulnerabilities: 152
Public exploits: 5
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Kibana Kibana is affected by 152 known vulnerabilities: 2 critical, 8 high, 40 medium, 102 low Critical High Medium Low

Vulnerabilities (152)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU142361 - Resource exhaustion
CWE-400 Medium
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU142359 - Missing Authorization
CVE-2026-72661
CWE-862 Low
No
No
8.19.19, 9.3.8, 9.4.4 13.08.2026 SB2026081368
#VU142358 - Allocation of Resources Without Limits or Throttling
CVE-2026-72653
CWE-770 Low
No
No
8.19.19, 9.3.8, 9.4.4 13.08.2026 SB2026081368
#VU142357 - Missing Authorization
CVE-2026-72669
CWE-862 Low
No
No
8.19.19, 9.4.5 13.08.2026 SB2026081368
#VU142356 - Uncaught Exception
CVE-2026-72660
CWE-248 Low
No
No
8.19.20, 9.3.8, 9.4.5 13.08.2026 SB2026081368
#VU142355 - Authorization Bypass Through User-Controlled Key
CVE-2026-72629
CWE-639 Low
No
No
8.19.20, 9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142354 - Incorrect Authorization
CVE-2026-72630
CWE-863 Low
No
No
8.19.20, 9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142353 - Observable discrepancy
CVE-2026-72632
CWE-203 Low
No
No
8.19.20, 9.4.5, 9.5.1 13.08.2026 SB2026081368
#VU142352 - Allocation of Resources Without Limits or Throttling
CVE-2026-72659
CWE-770 Low
No
No
8.19.20, 9.4.5 13.08.2026 SB2026081368
#VU139141 - Incomplete List of Disallowed Inputs
CVE-2026-63142
CWE-184 Low
No
No
8.19.19, 9.3.8, 9.4.4 22.07.2026 SB2026072275
#VU139140 - Incorrect Authorization
CVE-2026-63145
CWE-863 Low
No
No
8.19.19, 9.3.8, 9.4.4 22.07.2026 SB2026072275
#VU139139 - Resource exhaustion
CVE-2026-63260
CWE-400 Low
No
No
8.19.19, 9.3.8, 9.4.4 22.07.2026 SB2026072275
#VU139138 - Resource exhaustion
CVE-2026-63261
CWE-400 Low
No
No
8.19.19, 9.3.8, 9.4.4 22.07.2026 SB2026072275
#VU139137 - Allocation of Resources Without Limits or Throttling
CVE-2026-42397
CWE-770 Low
No
No
9.3.7, 9.4.4 22.07.2026 SB2026072275
#VU139136 - Missing Authorization
CVE-2026-63141
CWE-862 Low
No
No
9.3.8, 9.4.4 22.07.2026 SB2026072275
#VU139135 - Missing Authorization
CVE-2026-63143
CWE-862 Low
No
No
9.3.8, 9.4.4 22.07.2026 SB2026072275
#VU139134 - Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2026-49092
CWE-441 Low
No
No
9.4.3 22.07.2026 SB2026072275
#VU139133 - Improper Access Control
CVE-2026-56146
CWE-284 Low
No
No
9.4.3 22.07.2026 SB2026072275
#VU139132 - Authorization Bypass Through User-Controlled Key
CVE-2026-63259
CWE-639 Low
No
No
9.4.4 22.07.2026 SB2026072275
#VU139131 - Missing Authorization
CVE-2026-63262
CWE-862 Low
No
No
9.4.4 22.07.2026 SB2026072275


Showing elements 21 - 40 out of 152