<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:15:27.711825+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-elk-2026-78582</id>
    <title>BIT-elk-2026-78582 — Missing Authorization in Kibana Leading to Unauthorized Deletion of Data</title>
    <updated>2026-10-04T03:15:27.766129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: elk</p>
<p>Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-elk-2026-78582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1228</id>
    <title>certfr-2026-avi-1228 — De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-04T03:15:27.766202+00:00</updated>
    <content>certfr-2026-avi-1228</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1228"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-377332</id>
    <title>EUVD-2026-377332</title>
    <updated>2026-10-04T03:15:27.766246+00:00</updated>
    <content>EUVD-2026-377332</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-377332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-78582</id>
    <title>fkie_cve-2026-78582</title>
    <updated>2026-10-04T03:15:27.766268+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-78582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8638-62wr-x98m</id>
    <title>GHSA-8638-62wr-x98m</title>
    <updated>2026-10-04T03:15:27.766315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8638-62wr-x98m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3575</id>
    <title>WID-SEC-W-2026-3575 — Kibana: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:15:27.766359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um seine Privilegien zu erhöhen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3575"/>
  </entry>
</feed>
