Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-63138

Опубликовано: 01 сент. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
Версия от 9.4.0 (включая) до 9.4.5 (исключая)
cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00339
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-943

Связанные уязвимости

CVSS3: 6.5
redos
3 дня назад

Уязвимость kibana

CVSS3: 6.5
github
23 дня назад

Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.

EPSS

Процентиль: 27%
0.00339
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-943