<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:31:12.277284+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-elk-2026-72680</id>
    <title>BIT-elk-2026-72680 — Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unauthorized Data Modification</title>
    <updated>2026-10-03T10:31:12.343444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: elk</p>
<p>Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. As a result, an authenticated user holding only the Agent Builder read privilege can supply an identifier already in use by another user in the same space and cause that user's conversation to be replaced and reassigned to the requesting account. The original owner permanently loses access to the conversation and its history. The impact is limited to loss of integrity and availability of the affected conversation; the attacker does not read the overwritten content.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-elk-2026-72680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1020</id>
    <title>certfr-2026-avi-1020 — De multiples vulnérabilités ont été découvertes dans Elastic Kibana. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T10:31:12.343510+00:00</updated>
    <content>certfr-2026-avi-1020</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352351</id>
    <title>EUVD-2026-352351</title>
    <updated>2026-10-03T10:31:12.343534+00:00</updated>
    <content>EUVD-2026-352351</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72680</id>
    <title>fkie_cve-2026-72680</title>
    <updated>2026-10-03T10:31:12.343547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. As a result, an authenticated user holding only the Agent Builder read privilege can supply an identifier already in use by another user in the same space and cause that user's conversation to be replaced and reassigned to the requesting account. The original owner permanently loses access to the conversation and its history. The impact is limited to loss of integrity and availability of the affected conversation; the attacker does not read the overwritten content.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-72680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q63r-rpw5-hvr9</id>
    <title>GHSA-q63r-rpw5-hvr9</title>
    <updated>2026-10-03T10:31:12.343574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a conversation that does not exist and one that exists but belongs to another user. As a result, an authenticated user holding only the Agent Builder read privilege can supply an identifier already in use by another user in the same space and cause that user's conversation to be replaced and reassigned to the requesting account. The original owner permanently loses access to the conversation and its history. The impact is limited to loss of integrity and availability of the affected conversation; the attacker does not read the overwritten content.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q63r-rpw5-hvr9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2824</id>
    <title>WID-SEC-W-2026-2824 — Kibana: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:31:12.343593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um vertrauliche Informationen einschließlich Zugangsdaten offenzulegen, Daten und Konfigurationen zu manipulieren, Berechtigungen zu umgehen und einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2824"/>
  </entry>
</feed>
