Search
616 CVEs · published 2026-08-13 to 2026-08-13
CVEs (616, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 616 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-72658 | HIGH | 7.3 | 2026-08-13 | Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations … | |
| CVE-2026-72657 | MEDIUM | 6.5 | 2026-08-13 | Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The aut… | |
| CVE-2026-72656 | MEDIUM | 6.5 | 2026-08-13 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An … | |
| CVE-2026-72655 | MEDIUM | 4.3 | 2026-08-13 | Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unau… | |
| CVE-2026-72653 | MEDIUM | 6.5 | 2026-08-13 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is au… | |
| CVE-2026-72651 | MEDIUM | 6.5 | 2026-08-13 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read… | |
| CVE-2026-72650 | MEDIUM | 4.3 | 2026-08-13 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-… | |
| CVE-2026-72648 | MEDIUM | 6.5 | 2026-08-13 | Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedde… | |
| CVE-2026-72647 | MEDIUM | 6.5 | 2026-08-13 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only rea… | |
| CVE-2026-72645 | MEDIUM | 6.5 | 2026-08-13 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding onl… | |
| CVE-2026-72643 | HIGH | 7.1 | 2026-08-13 | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the us… | |
| CVE-2026-72642 | HIGH | 8.8 | 2026-08-13 | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset su… | |
| CVE-2026-72640 | MEDIUM | 6.5 | 2026-08-13 | The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each ref… | |
| CVE-2026-72639 | MEDIUM | 6.5 | 2026-08-13 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted… | |
| CVE-2026-72638 | MEDIUM | 6.5 | 2026-08-13 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged i… | |
| CVE-2026-72636 | MEDIUM | 6.5 | 2026-08-13 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to res… | |
| CVE-2026-72632 | HIGH | 7.1 | 2026-08-13 | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled… | |
| CVE-2026-72631 | MEDIUM | 6.5 | 2026-08-13 | Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare … | |
| CVE-2026-72630 | HIGH | 7.1 | 2026-08-13 | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration pol… | |
| CVE-2026-72629 | HIGH | 7.1 | 2026-08-13 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACL… | |
| CVE-2026-59714 | HIGH | Patched | 7.1 | 2026-08-13 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a messag… |
| CVE-2026-49864 | NONE | — | 2026-08-13 | wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and int… | |
| CVE-2026-49096 | MEDIUM | 4.3 | 2026-08-13 | Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not r… | |
| CVE-2026-49089 | MEDIUM | 6.5 | 2026-08-13 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by … | |
| CVE-2026-48099 | HIGH | 7.1 | 2026-08-13 | WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to e… |