<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 03:38:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15386</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15386</link>
      <description>bdu:2026-15386</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15386</guid>
    </item>
    <item>
      <title>BIT-elk-2026-63142 — Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery</title>
      <link>https://cve.radiocsirt.org/vuln/bit-elk-2026-63142</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: elk&lt;/p&gt;
&lt;p&gt;Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: elk&lt;/p&gt;
&lt;p&gt;Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-elk-2026-63142</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0906 — De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0906</link>
      <description>certfr-2026-avi-0906</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0906</guid>
    </item>
    <item>
      <title>EUVD-2026-339326</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339326</link>
      <description>EUVD-2026-339326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339326</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63142</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63142</link>
      <description>&lt;p&gt;Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63142</guid>
    </item>
    <item>
      <title>GHSA-mq6c-w86q-vpp3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mq6c-w86q-vpp3</link>
      <description>&lt;p&gt;Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mq6c-w86q-vpp3</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2464 — Kibana: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2464</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand auszulösen oder Daten offenzulegen und zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand auszulösen oder Daten offenzulegen und zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2464</guid>
    </item>
  </channel>
</rss>
