CVE Tools

Kibana

205 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Kibana, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Kibana CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Kibana CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-015
2025-020
2025-031
2025-042
2025-053
2025-062
2025-070
2025-081
2025-090
2025-104
2025-113
2025-126
2026-015
2026-025
2026-032
2026-045
2026-0510
2026-060
2026-0718
2026-0832
2026-0934

Severity

How the 205 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical115%
  • High4220%
  • Medium14973%
  • Low31%

Latest CVEs

The 15 most recently published vulnerabilities affecting Kibana.

  1. CVE-2026-94400Uncontrolled Resource Consumption in Kibana Leading to denial of service6.5
  2. CVE-2026-78582Missing Authorization in Kibana Leading to Unauthorized Deletion of Data6.5
  3. CVE-2026-72662Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data6.3
  4. CVE-2026-72668Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation7.3
  5. CVE-2026-82302Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification8.1
  6. CVE-2026-82299Incorrect Authorization in Kibana Leading to Information Disclosure6.5
  7. CVE-2026-82298Incorrect Authorization in Kibana Leading to Denial of Service4.3
  8. CVE-2026-78596Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations4.3
  9. CVE-2026-78595Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure4.3
  10. CVE-2026-78593Improper Control of Generation of Code in Kibana Leading to Privilege Escalation4.3
  11. CVE-2026-78583Incorrect Authorization in Kibana Leading to Privilege Escalation8.1
  12. CVE-2026-82293Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption4.3
  13. CVE-2026-78586Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service6.5
  14. CVE-2026-78584Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure4.3
  15. CVE-2026-78591Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana Leading to Unauthorized Resource Deletion6.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store