Exposure of Kibana
JavaScript graphics, Search engines78
exposure score
6
sites use
1
exploited
8
critical
Vexday analysis
Com 107 CVEs catalogadas, o Kibana apresenta taxa de exploração ativa 2,1 vezes acima da média geral do catálogo CISA KEV, o que indica uma superfície de ataque com histórico real de abuso, não apenas risco teórico. A CVE mais perigosa em exploração ativa é a CVE-2019-7609, com score EPSS de 0,95, sinalizando altíssima probabilidade de tentativas de exploração em ambientes expostos. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), relevante em ferramentas de visualização onde interfaces web são parte central da funcionalidade. O surgimento de 15 novas CVEs nos últimos 90 dias, combinado com 8 de severidade crítica, reforça a necessidade de manter o Kibana atualizado e com acesso devidamente restrito.
CVEs
186 resultsCVE-2026-72651MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72682MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72663MEDIUMInefficient Algorithmic Complexity in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72674MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72644MEDIUMUncaught Exception in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72652MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72653MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72667MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-63142MEDIUMIncomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request ForgeryEPSS 0.3%CVE-2026-63259MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-33461HIGHIncorrect Authorization in Kibana Fleet Leading to Information DisclosureEPSS 0.3%CVE-2021-22136—In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout settinEPSS 0.3%CVE-2026-72664MEDIUMMissing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response ActionsEPSS 0.3%CVE-2026-72666MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed HostsEPSS 0.3%CVE-2025-25010MEDIUMKibana privilege escalation via reporting_user roleEPSS 0.3%CVE-2026-72677HIGHRelative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other ResourcesEPSS 0.3%CVE-2026-78590HIGHImproper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged ResourcesEPSS 0.3%CVE-2026-72661MEDIUMMissing Authorization in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-26935MEDIUMImproper Input Validation in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-63262MEDIUMMissing Authorization in Kibana Leading to Information DisclosureEPSS 0.3%