Exposição de Kibana

JavaScript graphics, Search engines
78
score de exposição
6
sites usam
1
em exploração
8
críticos
Análise Vexday

Com 107 CVEs catalogadas, o Kibana apresenta taxa de exploração ativa 2,1 vezes acima da média geral do catálogo CISA KEV, o que indica uma superfície de ataque com histórico real de abuso, não apenas risco teórico. A CVE mais perigosa em exploração ativa é a CVE-2019-7609, com score EPSS de 0,95, sinalizando altíssima probabilidade de tentativas de exploração em ambientes expostos. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), relevante em ferramentas de visualização onde interfaces web são parte central da funcionalidade. O surgimento de 15 novas CVEs nos últimos 90 dias, combinado com 8 de severidade crítica, reforça a necessidade de manter o Kibana atualizado e com acesso devidamente restrito.

CVEs

186 resultados
CVE-2026-56146MEDIUMImproper Access Control in Kibana Leading to Unauthorized Data Modification and Information DisclosureEPSS 0.2%CVE-2026-33463MEDIUMOperation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized File AccessEPSS 0.2%CVE-2026-33462MEDIUMPath Traversal in Kibana Leading to Unauthorized Deletion of User AccountsEPSS 0.2%CVE-2026-72631MEDIUMImproper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API KeysEPSS 0.2%CVE-2026-72669HIGHMissing Authorization in Kibana Leading to Cross-User Information Disclosure and Data TamperingEPSS 0.2%CVE-2025-37728MEDIUMKibana Insufficiently Protected Credentials in the CrowdStrike ConnectorEPSS 0.2%CVE-2026-78591MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource DeletionEPSS 0.2%CVE-2025-25018HIGHKibana Stored Cross-Site Scripting (XSS)EPSS 0.2%CVE-2026-72675HIGHMissing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data ModificationEPSS 0.2%CVE-2026-33458MEDIUMServer-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information DisclosureEPSS 0.2%CVE-2026-78584MEDIUMObservable Response Discrepancy in Kibana Leading to Cross-Space Information DisclosureEPSS 0.2%CVE-2025-68422MEDIUMKibana Improper AuthorizationEPSS 0.2%CVE-2026-82299MEDIUMIncorrect Authorization in Kibana Leading to Information DisclosureEPSS 0.2%CVE-2026-78608MEDIUMMissing Authorization in Kibana Leading to Information DisclosureEPSS 0.2%CVE-2026-72641MEDIUMIncorrect Authorization in Kibana Leading to Unauthorized Modification of DataEPSS 0.2%CVE-2026-72673MEDIUMIncorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private LocationsEPSS 0.2%CVE-2026-72630HIGHIncorrect Authorization in Kibana Fleet Leading to Privilege EscalationEPSS 0.2%CVE-2026-72655MEDIUMImproperly Controlled Modification of Dynamically-Determined Object Attributes in Kibana Leading to Unauthorized Data ModificationEPSS 0.2%CVE-2026-78583HIGHIncorrect Authorization in Kibana Leading to Privilege EscalationEPSS 0.2%CVE-2026-82302HIGHIncorrect Authorization in Kibana Leading to Unauthorized Configuration ModificationEPSS 0.2%