Known vulnerabilities in Kibana - page 3

Software: Kibana
Software CPE: cpe:2.3:a:elastic_stack:kibana:*:*:*:*:*:*:*:*
Total vulnerabilities: 152
Public exploits: 5
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Kibana Kibana is affected by 152 known vulnerabilities: 2 critical, 8 high, 40 medium, 102 low Critical High Medium Low

Vulnerabilities (152)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139143 - Authorization Bypass Through User-Controlled Key
CVE-2026-56147
CWE-639 Low
No
No
8.19.18, 9.3.7, 9.4.3 22.07.2026 SB2026072275
#VU139142 - Resource exhaustion
CVE-2026-63139
CWE-400 Low
No
No
8.19.19, 9.3.8, 9.4.4 22.07.2026 SB2026072275
#VU136679 - Improper input validation
CVE-2026-56151
CWE-20 Low
No
No
8.19.17, 9.3.6, 9.4.3 02.07.2026 SB2026070217
#VU136678 - Allocation of Resources Without Limits or Throttling
CVE-2026-49087
CWE-770 Low
No
No
8.19.15, 9.3.4 02.07.2026 SB2026070216
#VU136677 - Information Exposure Through Log Files
CVE-2026-49088
CWE-532 Low
No
No
8.19.6, 9.0.8, 9.1.6 02.07.2026 SB2026070215
#VU136676 - Authorization Bypass Through User-Controlled Key
CVE-2026-49089
CWE-639 Low
No
No
8.16.3, 8.17.2 02.07.2026 SB2026070214
#VU136675 - Improper Output Neutralization for Logs
CVE-2026-49091
CWE-117 Medium
No
No
7.17.15, 8.11.1 02.07.2026 SB2026070213
#VU132766 - Resource exhaustion
CVE-2026-33464
CWE-400 Low
No
No
8.19.16, 9.3.5, 9.4.1 29.05.2026 SB2026052933
#VU132764 - Resource exhaustion
CVE-2026-49094
CWE-400 Low
No
No
8.19.16 29.05.2026 SB2026052933
#VU132763 - Resource exhaustion
CVE-2026-42399
CWE-400 Low
No
No
8.19.16, 9.3.5 29.05.2026 SB2026052933
#VU132762 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-33462
CWE-22 Low
No
No
8.19.16, 9.3.5 29.05.2026 SB2026052933
#VU132761 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-42401
CWE-79 Low
No
No
8.19.16, 9.3.5 29.05.2026 SB2026052933
#VU132760 - Resource exhaustion
CVE-2026-42400
CWE-400 Low
No
No
8.19.16, 9.3.5, 9.4.2 29.05.2026 SB2026052933
#VU132759 - Server-Side Request Forgery (SSRF)
CVE-2026-49093
CWE-918 Low
No
No
9.3.3 29.05.2026 SB2026052934
#VU132758 - Operation on a Resource after Expiration or Release
CVE-2026-33463
CWE-672 Medium
No
No
8.19.16, 9.3.5 29.05.2026 SB2026052933
#VU132757 - Improper input validation
CVE-2026-49095
CWE-20 Low
No
No
8.19.16, 9.3.5, 9.4.2 29.05.2026 SB2026052933
#VU125550 - Resource exhaustion
CVE-2026-33459
CWE-400 Medium
No
No
8.19.14, 9.2.8, 9.3.3 09.04.2026 SB2026040923
#VU125549 - Incorrect Authorization
CVE-2026-33460
CWE-863 Low
No
No
8.19.14, 9.2.8, 9.3.3 09.04.2026 SB2026040923
#VU125548 - Incorrect Authorization
CVE-2026-33461
CWE-863 Low
No
No
8.19.14, 9.2.8, 9.3.3 09.04.2026 SB2026040923
#VU125547 - Execution with Unnecessary Privileges
CVE-2026-4498
CWE-250 Low
No
No
8.19.14, 9.2.8, 9.3.3 09.04.2026 SB2026040923


Showing elements 41 - 60 out of 152