Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN722
_____________________________________________________________________


DATE                : 03/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Kibana.
 
=====================================================================

https://discuss.elastic.co/t/kibana-7-17-15-8-11-1-security-update-esa-2026-53
https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-45/387442
https://discuss.elastic.co/t/kibana-8-19-15-9-3-4-security-update-esa-2026-49/387444
https://discuss.elastic.co/t/kibana-8-18-9-8-19-6-9-0-8-9-1-6-security-update-esa-2026-50
_____________________________________________________________________



Kibana 7.17.15, 8.11.1 Security Update (ESA-2026-53)

kruskall July 1, 2026, 2:05pm 1

Improper Output Neutralization for Logs in Kibana Leading to Log
Injection

Improper Output Neutralization for Logs (CWE-117) in Kibana can lead
to log injection via Log Injection-Tampering-Forging (CAPEC-93). An
attacker can supply specially crafted input that is written to log
files without proper neutralization. When the log files are
subsequently viewed in a terminal that interprets control sequences, 
the injected content may alter the displayed log data.

Affected Versions:

    7.x: All versions up to and including 7.17.14
    8.x: All versions from 8.0.0 up to and including 8.11.0

Affected Configurations:

    All configurations are affected.

Solutions and Mitigations:

The issue is resolved in version 7.17.15 and 8.11.1.

For Users that Cannot Upgrade:

    Self-Managed: View Kibana log files only in tools that do not
interpret terminal control sequences.

    Cloud: The same guidance applies to Elastic Cloud Hosted
deployments.

Indicators of Compromise (IOC)

Inspect log files for unexpected terminal control or escape
sequences.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability
described in this security advisory was remediated in our
Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: High ( 8.0 ) - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE ID: CVE-2026-49091
Problem Type: CWE-117 - Improper Output Neutralization for Logs
Impact: CAPEC-93 - Log Injection-Tampering-Forging

_____________________________________________________________________



Kibana 8.19.17, 9.3.6, 9.4.3 Security Update (ESA-2026-45)
Announcements Security Announcements
kruskall July 1, 2026, 1:56pm 1

Improper Input Validation in Kibana Leading to Denial of Service

Improper Input Validation (CWE-20) in Kibana can lead to a denial of
service via Input Data Manipulation (CAPEC-153). An authenticated
user can submit a specially crafted Fleet policy input that is not
correctly validated, which can render Fleet agent, server, and
policy management functionality unavailable.

Affected Versions:

    8.x: All versions from 8.0.0 up to and including 8.19.16
    9.x:
        All versions from 9.0.0 up to and including 9.3.5
        All versions from 9.4.0 up to and including 9.4.2

Affected Configurations:

    Affects deployments that use Fleet. Exploitation requires an
authenticated account with privileges to manage Fleet policies.

Solutions and Mitigations:

The issue is resolved in version 8.19.17, 9.3.6, and 9.4.3.

For Users that Cannot Upgrade:

There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for
this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the
vulnerability described in this security advisory was
remediated in our Elastic Cloud Serverless offering before
the public disclosure.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-56151
Problem Type: CWE-20 - Improper Input Validation
Impact: CAPEC-153 - Input Data Manipulation

_____________________________________________________________________

Kibana 8.19.15, 9.3.4 Security Update (ESA-2026-49)
Announcements Security Announcements
kruskall July 1, 2026, 1:59pm 1

Allocation of Resources Without Limits or Throttling in Kibana Leading
to Denial of Service

Allocation of Resources Without Limits or Throttling (CWE-770) in
Kibana can lead to a denial of service via Excessive Allocation
(CAPEC-130). An authenticated user can submit a specially crafted
bulk deletion request that causes excessive resource consumption,
which may render Kibana unavailable.

Affected Versions:

    8.x: All versions from 8.0.0 up to and including 8.19.14
    9.x:
        All versions from 9.0.0 up to and including 9.3.3
        (9.4.0 and later not affected)

Affected Configurations:

    Affects deployments that use the Timeline feature. Exploitation
requires an authenticated account with access to Timeline.

Solutions and Mitigations:

The issue is resolved in version 8.19.15, and 9.3.4.

For Users that Cannot Upgrade:

There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for
this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the
vulnerability described in this security advisory was remediated
in our Elastic Cloud Serverless offering before the public
disclosure.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-49087
Problem Type: CWE-770 - Allocation of Resources Without Limits
         or Throttling
Impact: CAPEC-130 - Excessive Allocation

_____________________________________________________________________


Kibana 8.18.9, 8.19.6, 9.0.8, 9.1.6 Security Update (ESA-2026-50)
Announcements Security Announcements
kruskall July 1, 2026, 2:02pm 1

Insertion of Sensitive Information into Log File in Kibana Leading
to Information Disclosure

Insertion of Sensitive Information into Log File (CWE-532) in Kibana
can lead to information disclosure. When the optional application
performance monitoring (APM) instrumentation is enabled, sensitive
request header values could be recorded in application logs, where
they may be accessible to operators with log access.

Affected Versions:

    8.x:
        All versions from 8.0.0 up to and including 8.18.8
        All versions from 8.19.0 up to and including 8.19.5
    9.x:
        All versions from 9.0.0 up to and including 9.0.7
        All versions from 9.1.0 up to and including 9.1.5
        (9.2.0 and later not affected)

Affected Configurations:

    Affects deployments that explicitly enable APM instrumentation.
Deployments without APM instrumentation enabled are not affected.

Solutions and Mitigations:

The issue is resolved in version 8.18.9, 8.19.6, 9.0.8, and 9.1.6.

For Users that Cannot Upgrade:

    Self-Managed: Disable the optional APM instrumentation until
the deployment is upgraded.

    Cloud: This issue was remediated on Elastic-managed
infrastructure prior to disclosure; for self-configured Elastic
Cloud Hosted deployments, disable the optional APM instrumentation
until upgraded.

Indicators of Compromise (IOC)

Inspect application logs for recorded request header values
(including Cookie values); their presence indicates exposure.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the
vulnerability described in this security advisory was
remediated in our Elastic Cloud Serverless offering before
the public disclosure.

Severity: CVSSv3.1: Medium ( 4.4 ) - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
CVE ID: CVE-2026-49088
Problem Type: CWE-532 - Insertion of Sensitive Information
into Log File


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




