Exposição de Kibana
JavaScript graphics, Search engines78
score de exposição
6
sites usam
1
em exploração
8
críticos
Análise Vexday
Com 107 CVEs catalogadas, o Kibana apresenta taxa de exploração ativa 2,1 vezes acima da média geral do catálogo CISA KEV, o que indica uma superfície de ataque com histórico real de abuso, não apenas risco teórico. A CVE mais perigosa em exploração ativa é a CVE-2019-7609, com score EPSS de 0,95, sinalizando altíssima probabilidade de tentativas de exploração em ambientes expostos. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), relevante em ferramentas de visualização onde interfaces web são parte central da funcionalidade. O surgimento de 15 novas CVEs nos últimos 90 dias, combinado com 8 de severidade crítica, reforça a necessidade de manter o Kibana atualizado e com acesso devidamente restrito.
CVEs
186 resultadosCVE-2026-49089MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-78586MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-42400MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-42399MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-56147HIGHAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Information Disclosure and Case Attachment Integrity CompromiseEPSS 0.3%CVE-2024-11390MEDIUMKibana Unrestricted Upload of File with Dangerous Type Can Lead to XSSEPSS 0.3%CVE-2025-25016MEDIUMKibana Unrestricted Upload of FileEPSS 0.3%CVE-2026-26936MEDIUMInefficient Regular Expression Complexity in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-49088MEDIUMInsertion of Sensitive Information into Log File in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-49091HIGHImproper Output Neutralization for Logs in Kibana Leading to Log InjectionEPSS 0.3%CVE-2026-0530MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Excessive AllocationEPSS 0.3%CVE-2025-68389MEDIUMKibana Allocation of Resources Without Limits or ThrottlingEPSS 0.3%CVE-2026-72629HIGHAuthorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access to Machine Learning Trained ModelsEPSS 0.3%CVE-2026-78599MEDIUMStored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal ResourcesEPSS 0.3%CVE-2026-56152MEDIUMIncorrect Authorization in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-42398HIGHServer-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network AccessEPSS 0.3%CVE-2026-4498HIGHExecution with Unnecessary Privileges in Kibana Leading to reading index data beyond their direct Elasticsearch RBAC scopeEPSS 0.3%CVE-2026-72681MEDIUMMissing Authorization in Kibana Leading to Privilege Escalation and Information DisclosureEPSS 0.3%CVE-2026-33465MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72659MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%