# Elastic Kibana patches dozens of vulnerabilities

Published: 2026-08-14 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/7ebd9d9f-37e8-5e84-a614-1aa779502178/elastic-kibana-patches-dozens-of-vulnerabilities

> CERT-FR warns of multiple Kibana vulnerabilities allowing privilege escalation, DoS, CSRF, and data confidentiality breaches; patches available.

CERT-FR issued an advisory covering a large batch of vulnerabilities affecting Elastic Kibana versions prior to 8.19.20, 9.5.1, and 9.4.5. The flaws collectively enable privilege escalation, remote denial of service, data confidentiality and integrity breaches, security policy bypass, and cross-site request forgery (CSRF) attacks against affected deployments.

Elastic published over two dozen individual security bulletins (ESA-2026 series) on August 13, 2026, each addressing specific CVEs across the Kibana 8.x and 9.x branches. The advisory references more than 25 CVE identifiers, including one older CVE (CVE-2015-8131) alongside numerous 2026-dated vulnerabilities, indicating a comprehensive patch cycle rather than a single flaw. No active exploitation is reported; organizations running affected Kibana versions should apply the vendor patches referenced in the bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2015-8131, CVE-2026-49089, CVE-2026-72629, CVE-2026-72630, CVE-2026-72631, CVE-2026-72632, CVE-2026-72643, CVE-2026-72650, CVE-2026-72651, CVE-2026-72653, CVE-2026-72655, CVE-2026-72658, CVE-2026-72659, CVE-2026-72660, CVE-2026-72661, CVE-2026-72663, CVE-2026-72664, CVE-2026-72665, CVE-2026-72666, CVE-2026-72667, CVE-2026-72669, CVE-2026-72670, CVE-2026-72671, CVE-2026-72672, CVE-2026-72673, CVE-2026-72674, CVE-2026-72675, CVE-2026-72677, CVE-2026-72680, CVE-2026-72681

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1020

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7ebd9d9f-37e8-5e84-a614-1aa779502178/elastic-kibana-patches-dozens-of-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
