Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-72658 HIGH 7.3 2026-08-13 Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations …
CVE-2026-72657 MEDIUM 6.5 2026-08-13 Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The aut…
CVE-2026-72656 MEDIUM 6.5 2026-08-13 Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An …
CVE-2026-72655 MEDIUM 4.3 2026-08-13 Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unau…
CVE-2026-72653 MEDIUM 6.5 2026-08-13 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is au…
CVE-2026-72651 MEDIUM 6.5 2026-08-13 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read…
CVE-2026-72650 MEDIUM 4.3 2026-08-13 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-…
CVE-2026-72648 MEDIUM 6.5 2026-08-13 Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedde…
CVE-2026-72647 MEDIUM 6.5 2026-08-13 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only rea…
CVE-2026-72645 MEDIUM 6.5 2026-08-13 Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding onl…
CVE-2026-72643 HIGH 7.1 2026-08-13 Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the us…
CVE-2026-72642 HIGH 8.8 2026-08-13 The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset su…
CVE-2026-72640 MEDIUM 6.5 2026-08-13 The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each ref…
CVE-2026-72639 MEDIUM 6.5 2026-08-13 Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted…
CVE-2026-72638 MEDIUM 6.5 2026-08-13 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged i…
CVE-2026-72636 MEDIUM 6.5 2026-08-13 Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to res…
CVE-2026-72632 HIGH 7.1 2026-08-13 Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled…
CVE-2026-72631 MEDIUM 6.5 2026-08-13 Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare …
CVE-2026-72630 HIGH 7.1 2026-08-13 Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration pol…
CVE-2026-72629 HIGH 7.1 2026-08-13 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACL…
CVE-2026-59714 HIGH Patched 7.1 2026-08-13 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a messag…
CVE-2026-49864 NONE — 2026-08-13 wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and int…
CVE-2026-49096 MEDIUM 4.3 2026-08-13 Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not r…
CVE-2026-49089 MEDIUM 6.5 2026-08-13 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by …
CVE-2026-48099 HIGH 7.1 2026-08-13 WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to e…