[Git][security-tracker-team/security-tracker][master] Add new kibana issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 14:26:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5094dda7 by Salvatore Bonaccorso at 2026-08-14T15:25:44+02:00
Add new kibana issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -130,61 +130,61 @@ CVE-2026-72684 (A flaw in Elasticsearch allows an authenticated user holding onl
 CVE-2026-72683 (A flaw in Elasticsearch allows an authenticated user with the privileg ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72681 (Kibana Agent Builder does not correctly verify that the requesting use ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72680 (Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier  ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72679 (Elasticsearch does not apply its configurable input length restriction ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72678 (Elasticsearch does not validate a size value taken from a user-supplie ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72677 (Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorize ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72676 (Improper Control of Generation of Code ('Code Injection') (CWE-94) in  ...)
 	NOT-FOR-US: Fleet Server
 CVE-2026-72675 (Missing Authorization (CWE-862) in Kibana can lead to cross-space info ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72674 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72673 (Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized d ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72672 (The Elastic Security capability that suggests existing field values wh ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72671 (A Kibana Machine Learning capability that removes a saved object from  ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72670 (A lower privileged user who holds only the privilege to read agent pol ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72669 (The state that Kibana stores for an Observability Onboarding flow is n ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72667 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72666 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72665 (Missing Authorization (CWE-862) in Kibana can lead to unauthorized exe ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72664 (Missing Authorization (CWE-862) in Kibana can lead to unauthorized exe ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72663 (Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to den ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72661 (Missing Authorization (CWE-862) in Kibana can lead to information disc ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72660 (Uncaught Exception (CWE-248), resulting from Improper Input Validation ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72659 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72658 (Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege e ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72657 (Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Se ...)
 	NOT-FOR-US: Fleet Server
 CVE-2026-72656 (Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL que ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72655 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72653 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72651 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72650 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72648 (Cleartext Storage of Sensitive Information in an Environment Variable  ...)
 	TODO: check
 CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial o ...)
@@ -192,7 +192,7 @@ CVE-2026-72647 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to de
 CVE-2026-72645 (Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72643 (Kibana Agent Builder determines whether a caller owns a private agent  ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72642 (The native inference process that Elasticsearch uses to evaluate uploa ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72640 (The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret  ...)
@@ -204,13 +204,13 @@ CVE-2026-72638 (Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to de
 CVE-2026-72636 (Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matchin ...)
 	NOT-FOR-US: Elasticsearch
 CVE-2026-72632 (Observable Discrepancy (CWE-203) in Kibana Fleet can lead to informati ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72631 (Improper Privilege Management (CWE-269) in Kibana Fleet can lead to pr ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72630 (Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privileg ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-72629 (Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana c ...)
-	TODO: check
+	- kibana <itp> (bug #700337)
 CVE-2026-59714 (Open WebUI is an extensible, feature-rich, and user-friendly self-host ...)
 	TODO: check
 CVE-2026-49864 (wetty provides terminal access in browser over http/https. Prior to ve ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5094dda7e2e521b772d402b89fbf0a2aaf6057cb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5094dda7e2e521b772d402b89fbf0a2aaf6057cb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/86c44e4f/attachment.htm>


More information about the debian-security-tracker-commits mailing list