<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:21:23 +0000</lastBuildDate>
    <item>
      <title>BIT-elk-2026-72681 — Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/bit-elk-2026-72681</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: elk&lt;/p&gt;
&lt;p&gt;Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature&amp;#39;s functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: elk&lt;/p&gt;
&lt;p&gt;Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature&amp;#39;s functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-elk-2026-72681</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1020 — De multiples vulnérabilités ont été découvertes dans Elastic Kibana. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1020</link>
      <description>certfr-2026-avi-1020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1020</guid>
    </item>
    <item>
      <title>EUVD-2026-352380</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352380</link>
      <description>EUVD-2026-352380</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352380</guid>
    </item>
    <item>
      <title>fkie_cve-2026-72681</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72681</link>
      <description>&lt;p&gt;Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature&amp;#39;s functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature&amp;#39;s functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-72681</guid>
    </item>
    <item>
      <title>GHSA-9fww-g6xw-7wv9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9fww-g6xw-7wv9</link>
      <description>&lt;p&gt;Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature&amp;#39;s functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature&amp;#39;s functionality. This allows privilege escalation and could lead to disclosure of sensitive information that the user is not authorized to read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9fww-g6xw-7wv9</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2824 — Kibana: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2824</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um vertrauliche Informationen einschließlich Zugangsdaten offenzulegen, Daten und Konfigurationen zu manipulieren, Berechtigungen zu umgehen und einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um vertrauliche Informationen einschließlich Zugangsdaten offenzulegen, Daten und Konfigurationen zu manipulieren, Berechtigungen zu umgehen und einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2824</guid>
    </item>
  </channel>
</rss>
