Kibana 8.x < 8.19.20 / 9.x < 9.4.5 Multiple Vulnerabilities (ESA-2026-92 / ESA-2026-98 / ESA-2026-100 / ESA-2026-104 / ESA-2026-105 / ESA-2026-106 / ESA-2026-110)

high Nessus Plugin ID 338743

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Kibana installed on the remote host is 8.x prior to 8.19.20, or 9.x prior to 9.4.5. It is, therefore, affected by multiple vulnerabilities as referenced in the ESA-2026-92, ESA-2026-98, ESA-2026-100, ESA-2026-104, ESA-2026-105, ESA-2026-106 and ESA-2026-110 advisories.

- Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment. (CVE-2026-72675)

- Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted. (CVE-2026-72651)

- Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged access is not correctly validated before use. Processing the request causes unbounded memory growth in the Kibana process, which is terminated by the host once available memory is exhausted. Kibana then becomes unavailable to all users until the service is restarted. (CVE-2026-72659)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update to Kibana version 8.19.20, 9.4.5 or later.

See Also

http://www.nessus.org/u?2c2c4e7f

http://www.nessus.org/u?4210dad2

http://www.nessus.org/u?571facd0

http://www.nessus.org/u?6f400d16

http://www.nessus.org/u?84923ccd

http://www.nessus.org/u?bdf8d2c7

http://www.nessus.org/u?dc24a6ef

Plugin Details

Severity: High

ID: 338743

File Name: kibana_esa_2026_92.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.8

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:N

CVSS Score Source: CVE-2026-72675

CVSS v3

Risk Factor: High

Base Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Vulnerability Information

CPE: cpe:/a:elasticsearch:kibana

Required KB Items: installed_sw/Kibana

Patch Publication Date: 8/13/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-72650, CVE-2026-72651, CVE-2026-72655, CVE-2026-72659, CVE-2026-72663, CVE-2026-72667, CVE-2026-72675

CWE: 407, 639, 770, 862, 915

IAVB: 2026-B-0232