目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-63262— Elastic Kibana 授权问题漏洞

CVSS 4.3 · Medium EPSS 0.16% · P6

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
ElasticKibana9.4.0≤ 9.4.3affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-63262の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Missing Authorization in Kibana Leading to Information Disclosure
ソース: CVE Program / CVE List V5
脆弱性説明
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
授权机制缺失
ソース: CVE Program / CVE List V5
脆弱性タイトル
Elastic Kibana 授权问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Elastic kibana是荷兰Elastic公司开源的一个数据可视化平台。 Elastic Kibana 9.4.0版本至9.4.3版本存在授权问题漏洞,该漏洞源于授权缺失,可能导致信息泄露。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
ElasticKibana 9.4.0 ~ 9.4.3 -

II. CVE-2026-63262の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-63262のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-63262 厂商安全公告 (1)

Same Patch Batch · Elastic · 2026-07-21 · 19 CVEs total

CVE-2026-561477.1 HIGHAuthorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Informa
CVE-2026-423976.5 MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic
CVE-2026-632636.5 MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-632606.5 MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-632616.5 MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-631446.5 MEDIUMUncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-631406.5 MEDIUMReachable Assertion in Elasticsearch Leading to Denial of Service
CVE-2026-631366.5 MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-631396.5 MEDIUMUncontrolled Resource Consumption in Kibana Leading to Denial of Service
CVE-2026-561456.5 MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-631416.3 MEDIUMMissing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management
CVE-2026-561465.4 MEDIUMImproper Access Control in Kibana Leading to Unauthorized Data Modification and Informatio
CVE-2026-561445.3 MEDIUMIncorrect Authorization in Elasticsearch Leading to Information Disclosure
CVE-2026-631425.0 MEDIUMIncomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
CVE-2026-631434.3 MEDIUMMissing Authorization in Kibana Leading to Unauthorized Information Disclosure
CVE-2026-632594.3 MEDIUMAuthorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosu
CVE-2026-631454.3 MEDIUMIncorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromi
CVE-2026-490924.3 MEDIUMUnintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized Inf

IV. 関連脆弱性

V. CVE-2026-63262へのコメント

まだコメントはありません


コメントを残す