Synopsis
The remote host is affected by multiple vulnerabilities.
Description
The version of Kibana installed on the remote host is 8.x prior to 8.19.20, or 9.x prior to 9.4.5. It is, therefore, affected by multiple vulnerabilities as referenced in the ESA-2026-92, ESA-2026-98, ESA-2026-100, ESA-2026-104, ESA-2026-105, ESA-2026-106 and ESA-2026-110 advisories.
- Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment. (CVE-2026-72675)
- Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive resources. A single request is sufficient to leave Kibana unable to serve requests for all users until the process is restarted. (CVE-2026-72651)
- Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged access is not correctly validated before use. Processing the request causes unbounded memory growth in the Kibana process, which is terminated by the host once available memory is exhausted. Kibana then becomes unavailable to all users until the service is restarted. (CVE-2026-72659)
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update to Kibana version 8.19.20, 9.4.5 or later.
Plugin Details
File Name: kibana_esa_2026_92.nasl
Supported Sensors: Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:N
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Vulnerability Information
CPE: cpe:/a:elasticsearch:kibana
Required KB Items: installed_sw/Kibana
Patch Publication Date: 8/13/2026
Vulnerability Publication Date: 8/13/2026