These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-72653 is an Allocation of Resources Without Limits or Throttling (CWE-770) vulnerability in Kibana that can lead to denial of service via Excessive Allocation (CAPEC-130). The vulnerability was published on 2026-08-13T20:17:25.513Z and has not been modified since then. The NVD entry is currently Analyzed. Users of Elastic Kibana, especially those with maintenance window management privileges, sho [truncated]
The CVE-2026-72651 vulnerability, classified as Allocation of Resources Without Limits or Throttling (CWE-770), affects Kibana, potentially leading to denial of service via excessive allocation. An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. This issue is currently ra [truncated]
CVE-2026-72650 is an authorization bypass vulnerability in Kibana, allowing authenticated users to access alerting rule execution telemetry across spaces they are not authorized for. The disclosed telemetry includes rule identifiers, names, space identifiers, execution outcomes, timestamps, and counters. This vulnerability can be mitigated by restricting access to alerting rule execution telemetry based o [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-72648 is a Cleartext Storage of Sensitive Information vulnerability in Elastic Cloud on Kubernetes (ECK). During reconciliation of a Fleet Server resource that authenticates to Elasticsearch with a service account token, ECK writes the token in cleartext to the generated workload specification instead of referencing it from the K [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:24.673Z and has not been modified since then. The NVD entry is currently Analyzed. Elasticsearch's native inference process for machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays [truncated]
A user with limited Kubernetes permissions can exploit Elastic Cloud on Kubernetes (ECK) operator by writing an annotation on a secret, triggering a reconcile, and causing the operator to copy the contents of a secret from any other namespace into a secret the user can read. This unauthorized access could allow users to potentially access sensitive information from other namespaces, highlighting the need [truncated]
An executive overview of CVE-2026-72638: Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a specially crafted, malformed custom analysis definition that is resolved recursively without a cycle or depth check, exhausting the thread stack and termina [truncated]
The Elasticsearch wildcard matching helper is vulnerable to uncontrolled recursion, which can lead to a denial of service via excessive allocation. This vulnerability affects Elasticsearch clusters and can be exploited through search requests containing wildcard patterns with a large number of wildcard groups, evaluated against sufficiently long names. Elasticsearch administrators, security teams, and IT [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:23.937Z and has not been modified since then. CVE-2026-72631 is related to Improper Privilege Management (CWE-269) in Kibana Fleet, which could lead to privilege escalation. An integration policy may declare extra data streams that Fleet adds to the Elasticsearch API key issued to Elastic A [truncated]
The CVE-2026-72630 record describes an Incorrect Authorization vulnerability in Kibana Fleet, which can lead to privilege escalation via Privilege Abuse. This issue allows an authenticated user with the Elastic Defend endpoint policy management privilege to update an existing integration policy by providing a replacement integration, potentially leading to unauthorized access. Users and administrators of [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:23.690Z and has not been modified since then. This vulnerability, CVE-2026-72629, is an authorization bypass issue in Kibana that allows an attacker to access inference output from a trained model in a different space without proper authorization. The vulnerability has a CVSS score of 7.1 a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T20:17:22.600Z and has not been modified since then. The vulnerability is an uncaught exception in Kibana Cases that occurs when a malformed link syntax is stored in a case comment, causing the case to become inaccessible. Authenticated users with comment privileges can store such input, potential [truncated]
The CVE-2026-49089 vulnerability, classified as Allocation of Resources Without Limits or Throttling (CWE-770), affects Kibana and can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges can send a single request that leaves Kibana unable to serve any user until the process is restarted. This vulnerability impacts Kibana users with read-only priv [truncated]
CVE-2026-63263 is a vulnerability in Elasticsearch that can lead to denial of service via Exponential Data Expansion. An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. This could impact the availability of ES|QL queries, potentially disrupting service. The vulnerability is caused by uncontrolled resource consumpt [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T00:17:31.173Z and has not been modified since then. CVE-2026-63262 is a Missing Authorization vulnerability (CWE-862) in Kibana that can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control. Users of Elastic Kibana should revi [truncated]
CVE-2026-63261 is an Uncontrolled Resource Consumption vulnerability in Kibana, which can lead to denial of service via Excessive Allocation. A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The [truncated]
CVE-2026-63260 is a vulnerability in Kibana that can lead to denial of service via Excessive Allocation. An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payload. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of Kibana, especially those with low-privilege access, should be a [truncated]
CVE-2026-63259 is an authorization bypass vulnerability in Kibana, classified as CWE-639. This vulnerability allows for information disclosure through user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access. The vulnerability has a CVSS score of 4.3 and is considered medium severity. It was published on 2026-07-21T23:18:02.580Z and [truncated]
CVE-2026-63145 is an Incorrect Authorization vulnerability in Kibana's Machine Learning functionality. A low-privileged user with Machine Learning access can manipulate Machine Learning audit and notification records for arbitrary jobs by leveraging Kibana's internally elevated credentials. This vulnerability allows unauthorized modification of Machine Learning records, potentially leading to integrity co [truncated]
CVE-2026-63144 is a vulnerability in Elasticsearch that can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation component, causing a fatal error that terminates the affected node. In single-node deploy [truncated]
A user with limited feature privileges in Kibana can access workflow execution outputs in their Kibana space without required authorization, potentially leading to unauthorized information disclosure via Privilege Abuse (CAPEC-122). The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized [truncated]
CVE-2026-63142 is an Incomplete List of Disallowed Inputs vulnerability in Kibana. An authenticated attacker with access to the Reporting feature can bypass outbound request restrictions configured by an administrator. This causes the reporting service to send requests to network destinations that should be denied by the configured security policy. The vulnerability is classified under CWE-184 and affects [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:19:09.787Z and has not been modified since then. This Missing Authorization vulnerability in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without required feature privileges. The vulnerability is due to insufficient protection of pro [truncated]
CVE-2026-63140 is a Reachable Assertion vulnerability in Elasticsearch that can lead to denial of service via Input Data Manipulation. A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privilege [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T21:16:52.957Z and has not been modified since then. This CVE record details an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality, which can lead to denial of service via Excessive Allocation. An authenticated low-privileged user can exploit this vulnerability by sen [truncated]
CVE-2026-63136 is a vulnerability in Elasticsearch that can lead to denial of service via Excessive Allocation. A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. This issue affects Elasticsearch users with search privileges, administrators of Elasticsearch clusters, [truncated]
An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and delete case attachments that belong to feature areas they are not authorized to access. This vulnerability, CVE-2026-56147, is classified as an Authorization Bypass Through User-Controlled Key (CWE-639) and can lead to unauthorized information disclosure and case attachment inte [truncated]
CVE-2026-56146 is an Improper Access Control vulnerability in Kibana, allowing a low-privileged authenticated user with read-only Security Solution access to perform write operations on watchlist data. This could lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. Affected us [truncated]
A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessive memory consumption, causing the Elasticsearch node to crash. This vulnerability, known as Uncontrolled Resource Consumption (CWE-400), can lead to a denial of service via Excessive Allocation (CAPEC-130). The affected product is Elasti [truncated]
The CVE record for CVE-2026-49092 was published on 2026-07-21T20:17:01.610Z and has not been modified since then. The vulnerability, known as Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441), affects Kibana and can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data [truncated]