Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-72686 | MEDIUM | 6.5 | 2026-08-13 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component valida… | |
| CVE-2026-72685 | MEDIUM | 4.3 | 2026-08-13 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Proce… | |
| CVE-2026-72684 | MEDIUM | 6.5 | 2026-08-13 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that… | |
| CVE-2026-72683 | MEDIUM | 6.5 | 2026-08-13 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elastics… | |
| CVE-2026-72681 | MEDIUM | 6.5 | 2026-08-13 | Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that in… | |
| CVE-2026-72680 | MEDIUM | 6.5 | 2026-08-13 | Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does n… | |
| CVE-2026-72679 | MEDIUM | 6.5 | 2026-08-13 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives u… | |
| CVE-2026-72678 | MEDIUM | 6.5 | 2026-08-13 | Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated u… | |
| CVE-2026-72677 | HIGH | 7.3 | 2026-08-13 | Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-s… | |
| CVE-2026-72676 | MEDIUM | 6.5 | 2026-08-13 | Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-2… | |
| CVE-2026-72675 | HIGH | 7.1 | 2026-08-13 | Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine … | |
| CVE-2026-72674 | MEDIUM | 6.5 | 2026-08-13 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of docum… | |
| CVE-2026-72673 | MEDIUM | 5.4 | 2026-08-13 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (… | |
| CVE-2026-72672 | HIGH | 7.7 | 2026-08-13 | The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal … | |
| CVE-2026-72671 | MEDIUM | 4.3 | 2026-08-13 | A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privil… | |
| CVE-2026-72670 | HIGH | 7.7 | 2026-08-13 | A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the F… | |
| CVE-2026-72669 | HIGH | 7.6 | 2026-08-13 | The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verif… | |
| CVE-2026-72667 | MEDIUM | 6.5 | 2026-08-13 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request s… | |
| CVE-2026-72666 | MEDIUM | 6.8 | 2026-08-13 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the… | |
| CVE-2026-72665 | HIGH | 8.1 | 2026-08-13 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not… | |
| CVE-2026-72664 | MEDIUM | 6.5 | 2026-08-13 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Co… | |
| CVE-2026-72663 | MEDIUM | 6.5 | 2026-08-13 | Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression … | |
| CVE-2026-72661 | MEDIUM | 6.5 | 2026-08-13 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data… | |
| CVE-2026-72660 | MEDIUM | 6.5 | 2026-08-13 | Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authent… | |
| CVE-2026-72659 | MEDIUM | 6.5 | 2026-08-13 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed … |