Exposición de Kibana

JavaScript graphics, Search engines
78
score de exposición
6
sitios usan
1
en explotación
8
críticos
Análisis Vexday

Com 107 CVEs catalogadas, o Kibana apresenta taxa de exploração ativa 2,1 vezes acima da média geral do catálogo CISA KEV, o que indica uma superfície de ataque com histórico real de abuso, não apenas risco teórico. A CVE mais perigosa em exploração ativa é a CVE-2019-7609, com score EPSS de 0,95, sinalizando altíssima probabilidade de tentativas de exploração em ambientes expostos. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), relevante em ferramentas de visualização onde interfaces web são parte central da funcionalidade. O surgimento de 15 novas CVEs nos últimos 90 dias, combinado com 8 de severidade crítica, reforça a necessidade de manter o Kibana atualizado e com acesso devidamente restrito.

CVEs

186 resultados
CVE-2026-72663MEDIUMInefficient Algorithmic Complexity in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-72629HIGHAuthorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained ModelsEPSS 0.4%CVE-2024-37281MEDIUMKibana Denial of Service issueEPSS 0.4%CVE-2026-42398HIGHServer-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network AccessEPSS 0.4%CVE-2026-78592HIGHImproper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged ResourcesEPSS 0.4%CVE-2026-78590HIGHImproper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged ResourcesEPSS 0.4%CVE-2026-72677HIGHRelative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other ResourcesEPSS 0.4%CVE-2024-52974MEDIUMAn issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A succeEPSS 0.4%CVE-2026-72664MEDIUMMissing Authorization in Kibana Leading to Unauthorized Execution of Endpoint Response ActionsEPSS 0.4%CVE-2026-33463MEDIUMOperation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized File AccessEPSS 0.4%CVE-2026-82302HIGHIncorrect Authorization in Kibana Leading to Unauthorized Configuration ModificationEPSS 0.4%CVE-2026-78583HIGHIncorrect Authorization in Kibana Leading to Privilege EscalationEPSS 0.4%CVE-2026-33458MEDIUMServer-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information DisclosureEPSS 0.4%CVE-2026-72661MEDIUMMissing Authorization in Kibana Leading to Information DisclosureEPSS 0.4%CVE-2026-78608MEDIUMMissing Authorization in Kibana Leading to Information DisclosureEPSS 0.4%CVE-2026-82299MEDIUMIncorrect Authorization in Kibana Leading to Information DisclosureEPSS 0.4%CVE-2024-43708MEDIUMAn allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of iEPSS 0.4%CVE-2024-52972MEDIUMKibana allocation of resources without limits or throttling leads to crashEPSS 0.4%CVE-2026-72643HIGHIncorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private AgentsEPSS 0.4%CVE-2026-72672HIGHIncorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event DataEPSS 0.4%