{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aelastickibana/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2018-17245"},{"cvss":5.4,"id":"CVE-2026-56146"},{"cvss":6.5,"id":"CVE-2026-63139"},{"cvss":5,"id":"CVE-2026-63142"},{"cvss":4.3,"id":"CVE-2026-63143"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elasticsearch 8.x (prior to 8.19.19)","Elasticsearch 9.4.x (prior to 9.4.4)","Elasticsearch 9.x (prior to 9.3.8)","Kibana 8.x (prior to 8.19.19)","Kibana 9.4.x (prior to 9.4.4)","Kibana 9.x (prior to 9.3.8)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","elastic","elasticsearch","kibana","data-integrity","data-confidentiality","denial-of-service","ssrf"],"_cs_type":"advisory","_cs_vendors":["Elastic"],"content_html":"\u003cp\u003eCERT-FR has issued an advisory detailing multiple vulnerabilities discovered in Elastic products, specifically Elasticsearch and Kibana. These vulnerabilities, including CVE-2018-17245, CVE-2026-42397, CVE-2026-49092, and several others, affect various versions of Elasticsearch (8.x prior to 8.19.19, 9.4.x prior to 9.4.4, 9.x prior to 9.3.8) and Kibana (8.x prior to 8.19.19, 9.4.x prior to 9.4.4, 9.x prior to 9.3.8). If exploited, these flaws could allow an attacker to cause a remote denial of service, compromise the confidentiality and integrity of data, bypass security policies, or perform Server-Side Request Forgery (SSRF). Elastic has released security updates to address these issues, and users are urged to apply the recommended patches immediately to mitigate potential risks. This advisory was published on July 22, 2026, based on multiple Elastic security bulletins from July 21, 2026.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003cp\u003eThe provided source describes vulnerabilities and their potential impact but does not detail a specific attack chain or observed exploitation steps.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could lead to significant operational disruption and data compromise. Attackers could launch remote denial of service attacks, rendering critical Elasticsearch and Kibana services unavailable. Furthermore, the confidentiality and integrity of data stored and processed within these systems could be compromised, leading to unauthorized access, modification, or exfiltration of sensitive information. Security policy bypasses and Server-Side Request Forgery (SSRF) vulnerabilities introduce additional vectors for attackers to escalate privileges or access internal resources, potentially broadening the scope of an attack beyond the Elastic stack itself. The advisory does not mention specific observed attacks or victim counts, but the potential for data loss and service interruption for organizations relying on Elastic products is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patches provided by Elastic immediately, as detailed in the Elastic security bulletins referenced in this brief (e.g., \u003ca href=\"https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-54/388553)\"\u003ehttps://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-54/388553)\u003c/a\u003e, to update affected versions of Elasticsearch (e.g., to 8.19.19, 9.4.4, 9.3.8) and Kibana (e.g., to 8.19.19, 9.4.4, 9.3.8).\u003c/li\u003e\n\u003cli\u003eReview all listed CVEs (e.g., CVE-2026-42397, CVE-2026-49092, CVE-2026-56144) for potential impact on your specific Elastic deployments and prioritize patching based on the severity and accessibility of affected components.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T14:53:02Z","date_published":"2026-07-22T14:53:02Z","id":"https://feed.craftedsignal.io/briefs/2026-07-elastic-vulnerabilities/","summary":"CERT-FR has issued an advisory detailing multiple vulnerabilities in Elastic products, including CVE-2026-42397 and CVE-2026-49092, which could allow an attacker to cause remote denial of service, compromise data confidentiality and integrity, and perform Server-Side Request Forgery (SSRF).","title":"Multiple Vulnerabilities in Elastic Products","url":"https://feed.craftedsignal.io/briefs/2026-07-elastic-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}