Elastic Kibana patches dozens of vulnerabilities
CERT-FR warns of multiple Kibana vulnerabilities allowing privilege escalation, DoS, CSRF, and data confidentiality breaches; patches available.
CERT-FR issued an advisory covering a large batch of vulnerabilities affecting Elastic Kibana versions prior to 8.19.20, 9.5.1, and 9.4.5. The flaws collectively enable privilege escalation, remote denial of service, data confidentiality and integrity breaches, security policy bypass, and cross-site request forgery (CSRF) attacks against affected deployments.
Elastic published over two dozen individual security bulletins (ESA-2026 series) on August 13, 2026, each addressing specific CVEs across the Kibana 8.x and 9.x branches. The advisory references more than 25 CVE identifiers, including one older CVE (CVE-2015-8131) alongside numerous 2026-dated vulnerabilities, indicating a comprehensive patch cycle rather than a single flaw. No active exploitation is reported; organizations running affected Kibana versions should apply the vendor patches referenced in the bulletins.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1020
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free