elastic
115 known vulnerabilities affecting elastic products.
Products
kibana 76
elasticsearch 24
elastic_cloud_on_kubernetes 4
fleet_server 2
endpoint_security 1
filebeat 1
elastic_package_registry 1
apm_server 1
elastic_agent 1
logstash 1
maps_server 1
metricbeat 1
winlogbeat 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72652 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72682 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72667 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72645 | Low | 0.3% | 6.5 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead … | |
| CVE-2026-78588 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can l… | |
| CVE-2026-72644 | Low | 0.3% | 6.5 | Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input… | |
| CVE-2026-72647 | Low | 0.3% | 6.5 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service … | |
| CVE-2026-72653 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72659 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-78586 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72656 | Low | 0.3% | 6.5 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query process… | |
| CVE-2026-72687 | Low | 0.3% | 6.5 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a s… | |
| CVE-2026-72684 | Low | 0.3% | 6.5 | A flaw in Elasticsearch allows an authenticated user holding only read privilege… | |
| CVE-2026-72674 | Low | 0.3% | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lea… | |
| CVE-2026-72663 | Low | 0.3% | 6.5 | Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of ser… | |
| CVE-2026-63259 | Low | 0.3% | 4.3 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-63142 | Low | 0.3% | 5.0 | Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authentica… | |
| CVE-2026-78594 | Low | 0.3% | 4.9 | Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to … | |
| CVE-2026-72664 | Low | 0.3% | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of … | |
| CVE-2026-72657 | Low | 0.3% | 6.5 | Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can l… | |
| CVE-2026-72666 | Low | 0.3% | 6.8 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-49092 | Low | 0.3% | 4.3 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lea… | |
| CVE-2026-72661 | Low | 0.3% | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via… | |
| CVE-2026-63262 | Low | 0.3% | 4.3 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space i… | |
| CVE-2026-72640 | Low | 0.3% | 6.5 | The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references… | |
| CVE-2026-49094 | Low | 0.3% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-33459 | Low | 0.3% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of serv… | |
| CVE-2026-72685 | Low | 0.3% | 4.3 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index… | |
| CVE-2026-63145 | Low | 0.3% | 4.3 | Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of … | |
| CVE-2026-49095 | Low | 0.3% | 6.5 | Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management f… | |
| CVE-2026-72650 | Low | 0.3% | 4.3 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to… | |
| CVE-2026-63140 | Low | 0.2% | 6.5 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via… | |
| CVE-2026-63263 | Low | 0.2% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial … | |
| CVE-2026-63136 | Low | 0.2% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial … | |
| CVE-2026-63144 | Low | 0.2% | 6.5 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service … | |
| CVE-2026-56146 | Low | 0.2% | 5.4 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modificatio… | |
| CVE-2026-56144 | Low | 0.2% | 5.3 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated us… | |
| CVE-2026-72631 | Low | 0.2% | 6.5 | Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege es… | |
| CVE-2026-78591 | Low | 0.2% | 6.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (… | |
| CVE-2026-78587 | Low | 0.2% | 3.1 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of servic… | |
| CVE-2026-78584 | Low | 0.2% | 4.3 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead… | |
| CVE-2026-33458 | Low | 0.2% | 6.3 | Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to informa… | |
| CVE-2026-72641 | Low | 0.2% | 5.4 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modificatio… | |
| CVE-2026-72673 | Low | 0.2% | 5.4 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of… | |
| CVE-2026-78608 | Low | 0.2% | 6.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via… | |
| CVE-2026-72655 | Low | 0.2% | 4.3 | Improperly Controlled Modification of Dynamically-Determined Object Attributes (… | |
| CVE-2026-78605 | Low | 0.2% | 5.9 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444… | |
| CVE-2026-78601 | Low | 0.2% | 5.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via… | |
| CVE-2026-49096 | Low | 0.2% | 4.3 | Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via I… | |
| CVE-2026-49093 | Low | 0.2% | 6.3 | Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user … |