Exposición de Kibana
JavaScript graphics, Search engines78
score de exposición
6
sitios usan
1
en explotación
8
críticos
Análisis Vexday
Com 107 CVEs catalogadas, o Kibana apresenta taxa de exploração ativa 2,1 vezes acima da média geral do catálogo CISA KEV, o que indica uma superfície de ataque com histórico real de abuso, não apenas risco teórico. A CVE mais perigosa em exploração ativa é a CVE-2019-7609, com score EPSS de 0,95, sinalizando altíssima probabilidade de tentativas de exploração em ambientes expostos. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), relevante em ferramentas de visualização onde interfaces web são parte central da funcionalidade. O surgimento de 15 novas CVEs nos últimos 90 dias, combinado com 8 de severidade crítica, reforça a necessidade de manter o Kibana atualizado e com acesso devidamente restrito.
CVEs
186 resultadosCVE-2024-52973MEDIUMKibana allocation of resources without limits or throttling leads to crashEPSS 0.4%CVE-2026-33462MEDIUMPath Traversal in Kibana Leading to Unauthorized Deletion of User AccountsEPSS 0.4%CVE-2026-72666MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Query Execution on Managed HostsEPSS 0.4%CVE-2024-37279MEDIUMKibana Broken Access Control issueEPSS 0.4%CVE-2026-82293MEDIUMIncorrect Authorization in Kibana Leading to Unauthorized Resource ConsumptionEPSS 0.4%CVE-2026-82298MEDIUMIncorrect Authorization in Kibana Leading to Denial of ServiceEPSS 0.4%CVE-2026-78591MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource DeletionEPSS 0.4%CVE-2024-11390MEDIUMKibana Unrestricted Upload of File with Dangerous Type Can Lead to XSSEPSS 0.4%CVE-2026-78601MEDIUMMissing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data ExposureEPSS 0.3%CVE-2026-56147HIGHAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity CompromiseEPSS 0.3%CVE-2026-72632HIGHObservable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsearch API KeysEPSS 0.3%CVE-2026-72650MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2025-25016MEDIUMKibana Unrestricted Upload of FileEPSS 0.3%CVE-2024-23442MEDIUMKibana open redirect issueEPSS 0.3%CVE-2026-63143MEDIUMMissing Authorization in Kibana Leading to Unauthorized Information DisclosureEPSS 0.3%CVE-2026-26939MEDIUMMissing Authorization in Kibana Leading to Unauthorized Endpoint Response Action ConfigurationEPSS 0.3%CVE-2026-72631MEDIUMImproper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API KeysEPSS 0.3%CVE-2026-72669HIGHMissing Authorization in Kibana Leading to Cross-User Information Disclosure and Data TamperingEPSS 0.3%CVE-2026-49093MEDIUMServer-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network AccessEPSS 0.3%CVE-2026-49088MEDIUMInsertion of Sensitive Information into Log File in Kibana Leading to Information DisclosureEPSS 0.3%