<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:34:16.812711+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-elk-2026-72681</id>
    <title>BIT-elk-2026-72681 — Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure</title>
    <updated>2026-10-04T00:34:16.870415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: elk</p>
<p>Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-elk-2026-72681"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1020</id>
    <title>certfr-2026-avi-1020 — De multiples vulnérabilités ont été découvertes dans Elastic Kibana. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-04T00:34:16.870470+00:00</updated>
    <content>certfr-2026-avi-1020</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352380</id>
    <title>EUVD-2026-352380</title>
    <updated>2026-10-04T00:34:16.870491+00:00</updated>
    <content>EUVD-2026-352380</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72681</id>
    <title>fkie_cve-2026-72681</title>
    <updated>2026-10-04T00:34:16.870503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-72681"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9fww-g6xw-7wv9</id>
    <title>GHSA-9fww-g6xw-7wv9</title>
    <updated>2026-10-04T00:34:16.870526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9fww-g6xw-7wv9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2824</id>
    <title>WID-SEC-W-2026-2824 — Kibana: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:34:16.870542+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um vertrauliche Informationen einschließlich Zugangsdaten offenzulegen, Daten und Konfigurationen zu manipulieren, Berechtigungen zu umgehen und einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2824"/>
  </entry>
</feed>
