19 Total CVEs
19 AI Analyzed
0 CISA KEV
1 Critical

Profile

0% ended up actively exploited 0 of 19 added to CISA KEV
5% rated critical (CVSS 9.0+) 1 critical, 18 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

17 CVEs in the last 12 months

Products

  • Kibana3
  • Elasticsearch2
  • RBAC scope1

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-19 of 19 CVEs
CVE-2026-82302
Analyzed
8.1
Elastic Kibana

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control S...

2026-09-04
CVE-2026-78583
Analyzed
8.1
Elastic Kibana

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege...

2026-09-04
CVE-2026-72649
Analyzed
8.8
Elastic Elasticsearch

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CA...

2026-09-02
CVE-2026-72642
Analyzed
8.8
Elastic Elasticsearch

The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory add...

2026-08-14
CVE-2026-63137
Analyzed
8.3
Elastic Kibana

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAP...

2026-09-02
CVE-2026-4498
Analyzed
7.7
Elastic RBAC scope

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elastics...

2026-04-09
CVE-2026-33466
Analyzed
8.1
Elastic Multiple Products

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code executio...

2026-04-09
CVE-2026-33461
Analyzed
7.7
Elastic Multiple Products

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122)

2026-04-09
CVE-2026-26938
Analyzed
8.6
Elastic Multiple Products

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read a...

2026-02-27
CVE-2026-0532
Analyzed
8.6
Elastic Multiple Products

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file discl...

2026-01-15
CVE-2025-68385
Analyzed
7.2
Elastic Multiple Products

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script...

2025-12-20
CVE-2025-37736
Analyzed
8.8
Elastic Multiple Products

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be...

2025-11-08
CVE-2025-37735
Analyzed
7
Elastic Multiple Products

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service...

2025-11-06
CVE-2025-37729
Analyzed
9.1
Elastic Multiple Products

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin acces...

2025-10-13
CVE-2025-25018
Analyzed
8.7
Elastic Multiple Products

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

2025-10-10
CVE-2025-25017
Analyzed
8.2
Elastic Multiple Products

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

2025-10-10
CVE-2025-25011
Analyzed
7
Elastic Multiple Products

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions

2025-07-30
CVE-2025-25009
Analyzed
8.7
Elastic Multiple Products

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload

2025-10-07
CVE-2025-0712
Analyzed
7
Elastic Multiple Products

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions

2025-07-30