Vulnerabilities in Elastic

352 results
Vexday analysis

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2026-49088MEDIUMInsertion of Sensitive Information into Log File in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-49091HIGHImproper Output Neutralization for Logs in Kibana Leading to Log InjectionEPSS 0.3%CVE-2026-0530MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Excessive AllocationEPSS 0.3%CVE-2025-68389MEDIUMKibana Allocation of Resources Without Limits or ThrottlingEPSS 0.3%CVE-2026-72629HIGHAuthorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained ModelsEPSS 0.3%CVE-2026-56143MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-78599MEDIUMStored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal ResourcesEPSS 0.3%CVE-2026-72648MEDIUMCleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information DisclosureEPSS 0.3%CVE-2026-56152MEDIUMIncorrect Authorization in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-72636MEDIUMUncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of ServiceEPSS 0.3%CVE-2026-4498HIGHExecution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scopeEPSS 0.3%CVE-2026-72681MEDIUMMissing Authorization in Kibana Leading to Privilege Escalation and Information DisclosureEPSS 0.3%CVE-2026-42398HIGHServer-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network AccessEPSS 0.3%CVE-2026-72645MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-72653MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72684MEDIUMAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-72638MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-72647MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-33465MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72656MEDIUMMemory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of ServiceEPSS 0.3%