VORANT. Threat Intelligence Sign in Get the full feed

Elastic Kibana patches dozens of vulnerabilities

routine vulnerability technology

CERT-FR warns of multiple Kibana vulnerabilities allowing privilege escalation, DoS, CSRF, and data confidentiality breaches; patches available.

CERT-FR issued an advisory covering a large batch of vulnerabilities affecting Elastic Kibana versions prior to 8.19.20, 9.5.1, and 9.4.5. The flaws collectively enable privilege escalation, remote denial of service, data confidentiality and integrity breaches, security policy bypass, and cross-site request forgery (CSRF) attacks against affected deployments.

Elastic published over two dozen individual security bulletins (ESA-2026 series) on August 13, 2026, each addressing specific CVEs across the Kibana 8.x and 9.x branches. The advisory references more than 25 CVE identifiers, including one older CVE (CVE-2015-8131) alongside numerous 2026-dated vulnerabilities, indicating a comprehensive patch cycle rather than a single flaw. No active exploitation is reported; organizations running affected Kibana versions should apply the vendor patches referenced in the bulletins.

Mentioned in this report

Vulnerabilities CVE-2015-8131CVE-2026-49089CVE-2026-72629CVE-2026-72630CVE-2026-72631CVE-2026-72632CVE-2026-72643CVE-2026-72650CVE-2026-72651CVE-2026-72653CVE-2026-72655CVE-2026-72658CVE-2026-72659CVE-2026-72660CVE-2026-72661CVE-2026-72663CVE-2026-72664CVE-2026-72665CVE-2026-72666CVE-2026-72667CVE-2026-72669CVE-2026-72670CVE-2026-72671CVE-2026-72672CVE-2026-72673CVE-2026-72674CVE-2026-72675CVE-2026-72677CVE-2026-72680CVE-2026-72681

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1020

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free