Vulnerabilidades em Elastic

352 resultados
Análise Vexday

Com 233 CVEs catalogadas, o ecossistema Elastic apresenta taxa de exploração ativa em linha com a média geral do catálogo, o que não elimina pontos de atenção relevantes. O CVE-2019-7609, única entrada confirmada no CISA KEV, carrega EPSS de 0,9534 — valor extremamente elevado que indica alta probabilidade de exploração ativa e deve ser prioridade absoluta para equipes que ainda não aplicaram a correção correspondente. O tipo de falha mais frequente, CWE-79 (Cross-Site Scripting), sugere que controles de sanitização de entrada e saída merecem atenção sistemática no ciclo de desenvolvimento e hardening das implantações. As 17 CVEs surgidas nos últimos 90 dias e a existência de 3 vulnerabilidades com PoC pública reforçam a necessidade de monitoramento contínuo, especialmente em ambientes expostos.

CVE-2026-49092MEDIUMUnintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Information ExposureEPSS 0.3%CVE-2026-26935MEDIUMImproper Input Validation in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-63262MEDIUMMissing Authorization in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-72661MEDIUMMissing Authorization in Kibana Leading to Information DisclosureEPSS 0.3%CVE-2026-72677HIGHRelative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Other ResourcesEPSS 0.3%CVE-2026-78590HIGHImproper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthorized Deletion of Privileged ResourcesEPSS 0.3%CVE-2025-25017HIGHKibana Stored Cross-Site Scripting (XSS)EPSS 0.3%CVE-2026-26934MEDIUMImproper Validation of Specified Quantity in Input in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-33464MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72672HIGHIncorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event DataEPSS 0.3%CVE-2024-52975CRITICALFleet Server sensitive information exposure via logsEPSS 0.3%CVE-2026-72640MEDIUMUnintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret DisclosureEPSS 0.3%CVE-2026-26937MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-26940MEDIUMImproper Validation of Specified Quantity in Input in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-49094MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-33459MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-72665HIGHMissing Authorization in Kibana Leading to Unauthorized Execution of Host Response ActionsEPSS 0.3%CVE-2026-63145MEDIUMIncorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity CompromiseEPSS 0.3%CVE-2026-72685MEDIUMInefficient Algorithmic Complexity in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-72643HIGHIncorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tampering of Private AgentsEPSS 0.3%