| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-72675 | Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Disclosure and Unauthorized Data Modification | Elastic | Kibana | High | 7.1 | 2026-08-13 19:11:24 | Deep Dive |
| CVE-2026-72674 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service | Elastic | Kibana | Medium | 6.5 | 2026-08-13 19:11:22 | Deep Dive |
| CVE-2026-72673 | Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private Locations | Elastic | Kibana | Medium | 5.4 | 2026-08-13 19:11:20 | Deep Dive |
| CVE-2026-72672 | Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event Data | Elastic | Kibana | High | 7.7 | 2026-08-13 19:11:17 | Deep Dive |
| CVE-2026-72671 | Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning Trained Model Space Assignments | Elastic | Kibana | Medium | 4.3 | 2026-08-13 19:11:15 | Deep Dive |
| CVE-2026-72670 | Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosure of Fleet Proxy Credentials | Elastic | Kibana | High | 7.7 | 2026-08-13 19:11:13 | Deep Dive |
| CVE-2026-72669 | Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tampering | Elastic | Kibana | High | 7.6 | 2026-08-13 19:11:11 | Deep Dive |
| CVE-2026-72681 | Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure | Elastic | Kibana | Medium | 6.5 | 2026-08-13 19:11:09 | Deep Dive |
| CVE-2026-72680 | Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data Modification | Elastic | Kibana | Medium | 6.5 | 2026-08-13 19:11:07 | Deep Dive |
| CVE-2026-72679 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service | Elastic | Elasticsearch | Medium | 6.5 | 2026-08-13 19:11:05 | Deep Dive |
| CVE-2026-72678 | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service | Elastic | Elasticsearch | Medium | 6.5 | 2026-08-13 19:11:03 | Deep Dive |
| CVE-2026-72687 | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service | Elastic | Elasticsearch | Medium | 6.5 | 2026-08-13 19:11:00 | Deep Dive |
| CVE-2026-72686 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service | Elastic | Elasticsearch | Medium | 6.5 | 2026-08-13 19:10:58 | Deep Dive |
| CVE-2026-72685 | Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of Service | Elastic | Elasticsearch | Medium | 4.3 | 2026-08-13 19:10:56 | Deep Dive |
| CVE-2026-72684 | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service | Elastic | Elasticsearch | Medium | 6.5 | 2026-08-13 19:10:54 | Deep Dive |
| CVE-2026-72683 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service | Elastic | Elasticsearch | Medium | 6.5 | 2026-08-13 19:10:51 | Deep Dive |
| CVE-2026-59714🧪 | Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) | open-webui | open-webui | High | 7.1 | 2026-08-13 19:10:42 | Deep Dive |
| CVE-2026-49864🧪 | wetty vulnerable to DOM XSS via file-download filename | butlerx | wetty | High | 8.6 | 2026-08-13 19:10:41 | Deep Dive |
| CVE-2026-49089 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service | Elastic | Kibana | Medium | 6.5 | 2026-08-13 19:08:07 | Deep Dive |
| CVE-2026-73531 | django-helpdesk < 2.3.3 Stored XSS via HTML Attachments | django-helpdesk | django-helpdesk | Medium | 6.1 | 2026-08-13 19:06:12 | Deep Dive |