PatchSiren

Elastic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Elastic CVE published 2026-07-22

CVE-2026-63263

CVE-2026-63263 is a vulnerability in Elasticsearch that can lead to denial of service via Exponential Data Expansion. An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. This could impact the availability of ES|QL queries, potentially disrupting service. The vulnerability is caused by uncontrolled resource consumpt [truncated]

MEDIUM Elastic CVE published 2026-07-22

CVE-2026-63262

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T00:17:31.173Z and has not been modified since then. CVE-2026-63262 is a Missing Authorization vulnerability (CWE-862) in Kibana that can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control. Users of Elastic Kibana should revi [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63261

CVE-2026-63261 is an Uncontrolled Resource Consumption vulnerability in Kibana, which can lead to denial of service via Excessive Allocation. A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63260

CVE-2026-63260 is a vulnerability in Kibana that can lead to denial of service via Excessive Allocation. An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payload. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of Kibana, especially those with low-privilege access, should be a [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63259

CVE-2026-63259 is an authorization bypass vulnerability in Kibana, classified as CWE-639. This vulnerability allows for information disclosure through user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access. The vulnerability has a CVSS score of 4.3 and is considered medium severity. It was published on 2026-07-21T23:18:02.580Z and [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63145

CVE-2026-63145 is an Incorrect Authorization vulnerability in Kibana's Machine Learning functionality. A low-privileged user with Machine Learning access can manipulate Machine Learning audit and notification records for arbitrary jobs by leveraging Kibana's internally elevated credentials. This vulnerability allows unauthorized modification of Machine Learning records, potentially leading to integrity co [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63144

CVE-2026-63144 is a vulnerability in Elasticsearch that can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation component, causing a fatal error that terminates the affected node. In single-node deploy [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63143

A user with limited feature privileges in Kibana can access workflow execution outputs in their Kibana space without required authorization, potentially leading to unauthorized information disclosure via Privilege Abuse (CAPEC-122). The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63142

CVE-2026-63142 is an Incomplete List of Disallowed Inputs vulnerability in Kibana. An authenticated attacker with access to the Reporting feature can bypass outbound request restrictions configured by an administrator. This causes the reporting service to send requests to network destinations that should be denied by the configured security policy. The vulnerability is classified under CWE-184 and affects [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63141

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:19:09.787Z and has not been modified since then. This Missing Authorization vulnerability in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without required feature privileges. The vulnerability is due to insufficient protection of pro [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63140

CVE-2026-63140 is a Reachable Assertion vulnerability in Elasticsearch that can lead to denial of service via Input Data Manipulation. A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privilege [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63139

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T21:16:52.957Z and has not been modified since then. This CVE record details an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality, which can lead to denial of service via Excessive Allocation. An authenticated low-privileged user can exploit this vulnerability by sen [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-63136

CVE-2026-63136 is a vulnerability in Elasticsearch that can lead to denial of service via Excessive Allocation. A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. This issue affects Elasticsearch users with search privileges, administrators of Elasticsearch clusters, [truncated]

HIGH Elastic CVE published 2026-07-21

CVE-2026-56147

An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and delete case attachments that belong to feature areas they are not authorized to access. This vulnerability, CVE-2026-56147, is classified as an Authorization Bypass Through User-Controlled Key (CWE-639) and can lead to unauthorized information disclosure and case attachment inte [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-56146

CVE-2026-56146 is an Improper Access Control vulnerability in Kibana, allowing a low-privileged authenticated user with read-only Security Solution access to perform write operations on watchlist data. This could lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Affected us [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-56145

A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory consumption, causing the Elasticsearch node to crash. This vulnerability, known as Uncontrolled Resource Consumption (CWE-400), can lead to a denial of service via Excessive Allocation (CAPEC-130). The affected product is Elasti [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-49092

The CVE record for CVE-2026-49092 was published on 2026-07-21T20:17:01.610Z and has not been modified since then. The vulnerability, known as Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441), affects Kibana and can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data [truncated]

MEDIUM Elastic CVE published 2026-07-21

CVE-2026-42397

CVE-2026-42397 is a denial of service via excessive allocation vulnerability in Elastic Kibana. An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value that causes excessive resource consumption, which may render Kibana unavailable. This vulnerability, classified as CWE-770 (Allocation of Resources Without Limits or Throttling [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-49095

CVE-2026-49095 is a medium-severity (CVSS 6.5) improper input validation vulnerability (CWE-20) in Kibana's Fleet agent policy management feature, published 2026-05-28. An authenticated attacker with Fleet management privileges can inject malicious values into configuration overrides, causing Elastic Agents to receive API keys with elevated Elasticsearch privileges. This grants unauthorized read/write acc [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-49094

A denial-of-service vulnerability in Kibana allows authenticated users with viewer-level permissions to trigger excessive CPU and memory consumption by submitting oversized input values to an analytics collections management endpoint. The vulnerability stems from uncontrolled resource consumption (CWE-400) during request processing, causing Kibana to become unavailable to all users until manual service re [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-49093

A Server-Side Request Forgery (SSRF) vulnerability in Kibana allows authenticated users with connector management privileges to bypass operator-configured connector allowlists. The flaw enables outbound requests from the Kibana server to destinations that egress controls were designed to block. This vulnerability is rated MEDIUM severity with a CVSS score of 6.3. The issue was disclosed on May 28, 2026, w [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-42400

A medium-severity uncontrolled resource consumption vulnerability in Kibana allows authenticated remote attackers to cause denial of service through excessive memory and CPU consumption. The vulnerability stems from processing of specially crafted compressed request payloads that occurs prior to authorization checks, enabling resource exhaustion attacks that can render Kibana instances unresponsive or cau [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-42399

A denial-of-service vulnerability in Kibana's Timelion visualization engine allows authenticated low-privileged users to trigger uncontrolled memory consumption. The flaw stems from improper handling of deeply chained function calls in Timelion expressions, causing exponential growth of internal data structures that exhaust available memory and crash the Kibana service. This affects availability for all u [truncated]

HIGH Elastic CVE published 2026-05-28

CVE-2026-42398

A Server-Side Request Forgery (SSRF) vulnerability in Kibana allows authenticated users with connector management privileges to bypass operator-configured egress restrictions. The flaw exists in the Webhook connector functionality, where crafted target configurations can cause Kibana to issue outbound requests to destinations that should be blocked by allowlist controls. This represents a scope change (S: [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-42401

A stored HTML injection vulnerability in Kibana allows users with write access to an Elasticsearch index to persist unsanitized markup. When another user views affected Kibana views, the crafted content renders without adequate sanitization, potentially enabling unauthorized UI manipulation and outbound network requests from the victim's browser session. The vulnerability stems from improper neutralizatio [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-33464

CVE-2026-33464 is a medium-severity uncontrolled resource consumption vulnerability in Kibana, published 2026-05-28. An authenticated low-privileged user can submit an oversized payload to an internal Kibana API, causing resource exhaustion and denial of service. The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) with attack pattern CAPEC-130 (Excessive Allocation). CVSS 3.1 sc [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-33463

A logic error in Kibana's time-bounded access token validation allows expired tokens to remain usable, enabling unauthorized information disclosure. The vulnerability stems from improper expiration timestamp validation (CWE-672), where tokens are not properly invalidated after their intended validity window expires. An unauthenticated actor in possession of such a token can retrieve associated content bey [truncated]

MEDIUM Elastic CVE published 2026-05-28

CVE-2026-33462

A path traversal vulnerability in Kibana's dashboard management functionality allows an authenticated low-privilege user to craft a malicious dashboard identifier. When an administrator subsequently deletes this dashboard through the Kibana interface, the deletion request is redirected to an unintended internal endpoint, potentially causing unauthorized deletion of user accounts or other resources. The at [truncated]

HIGH Elastic CVE published 2026-04-08

CVE-2026-4498

CVE-2026-4498 is a high-severity vulnerability in Elastic Kibana's Fleet plugin, allowing authenticated users with Fleet sub-feature privileges to read index data beyond their direct Elasticsearch RBAC scope. This issue arises from insufficient privilege checks in the Fleet plugin's debug route handlers, potentially leading to unauthorized data access. Users of Elastic Kibana, especially those with Fleet [truncated]

HIGH Elastic CVE published 2026-01-14

CVE-2026-0532

CVE-2026-0532 is a critical vulnerability that combines External Control of File Name or Path (CWE-73) with Server-Side Request Forgery (CWE-918). This allows an attacker with authenticated access and sufficient privileges to create or modify connectors to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. The vulnerability ex [truncated]

Known exploited Elastic CVE published 2022-03-25

CVE-2015-1427

CVE-2015-1427 is a remote code execution issue associated with Elasticsearch’s Groovy scripting engine and is listed by CISA as a Known Exploited Vulnerability. For defenders, that means the risk is not theoretical: affected Elasticsearch deployments should be treated as patch-priority work and updated according to vendor instructions.

Known exploited Elastic CVE published 2022-03-25

CVE-2014-3120

CVE-2014-3120 is a remote code execution issue affecting Elastic Elasticsearch and is listed in CISA’s Known Exploited Vulnerabilities catalog. CISA’s record indicates the issue has known exploitation activity and directs defenders to apply updates per vendor instructions.

Known exploited Elastic CVE published 2022-01-10

CVE-2019-7609

CVE-2019-7609 is a Kibana arbitrary code execution vulnerability associated with Elastic. CISA added it to the Known Exploited Vulnerabilities catalog, which indicates known exploitation and makes patching a priority for defenders. The supplied authoritative sources identify the issue, but provide limited technical detail in this corpus; the safe response is to inventory affected Kibana deployments and ap [truncated]