Exposure of Kibana
JavaScript graphics, Search engines78
exposure score
6
sites use
1
exploited
8
critical
Vexday analysis
Com 107 CVEs catalogadas, o Kibana apresenta taxa de exploração ativa 2,1 vezes acima da média geral do catálogo CISA KEV, o que indica uma superfície de ataque com histórico real de abuso, não apenas risco teórico. A CVE mais perigosa em exploração ativa é a CVE-2019-7609, com score EPSS de 0,95, sinalizando altíssima probabilidade de tentativas de exploração em ambientes expostos. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), relevante em ferramentas de visualização onde interfaces web são parte central da funcionalidade. O surgimento de 15 novas CVEs nos últimos 90 dias, combinado com 8 de severidade crítica, reforça a necessidade de manter o Kibana atualizado e com acesso devidamente restrito.
CVEs
186 resultsCVE-2026-49092MEDIUMUnintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information ExposureEPSS 0.3%CVE-2025-25017HIGHKibana Stored Cross-Site Scripting (XSS)EPSS 0.3%CVE-2026-33464MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-26934MEDIUMImproper Validation of Specified Quantity in Input in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72672HIGHIncorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event DataEPSS 0.3%CVE-2026-26937MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-26940MEDIUMImproper Validation of Specified Quantity in Input in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-49094MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-33459MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72665HIGHMissing Authorization in Kibana Leading to Unauthorized Execution of Host Response ActionsEPSS 0.3%CVE-2026-63145MEDIUMIncorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity CompromiseEPSS 0.3%CVE-2026-72643HIGHIncorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private AgentsEPSS 0.3%CVE-2026-49095HIGHImproper Input Validation in Kibana Fleet Leading to Privilege EscalationEPSS 0.3%CVE-2024-43710MEDIUMKibana server-side request forgeryEPSS 0.3%CVE-2026-72650MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-26938HIGHImproper Neutralization of Special Elements Used in a Template Engine in Kibana Workflows Leading to Server-Side Request Forgery (SSRF)EPSS 0.3%CVE-2026-72632HIGHObservable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API KeysEPSS 0.3%CVE-2025-68385HIGHKibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.3%CVE-2026-78592HIGHImproper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged ResourcesEPSS 0.3%CVE-2025-25009HIGHKibana Cross-Site Scripting (XSS)EPSS 0.2%