Kibana Vulnerabilities Enable SSRF and XSS Attacks
Article Content
Browse articles
Multiple vulnerabilities in Kibana have been identified, allowing attackers to execute Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS) attacks. These vulnerabilities potentially expose systems to unauthorized access and data manipulation. Organizations using Kibana are advised to assess their security measures in light of these findings.
Ask AI about this cluster
Answers cite the sources they use
Updated 209d ago How this analysis works
More articles in this cluster (2)
Continue Reading
High-Risk SSRF Vulnerability in Privoce VoceChat Server Disclosed A critical vulnerability, CVE-2026-100893, has been identified in the Privoce VoceChat Server up to version 0.5.36. This vulnerability allows remote attackers to exploit the open_graph::fetch function by manipulating the URL parameter, leading to server-side request forgery (SSRF). The attack can be executed without…
CVE-2026-92602: TDuckCloud Survey Form Vulnerability Exposes User Data A vulnerability identified as CVE-2026-92602 affects the TDuck survey form through version 5.3, allowing authenticated attackers to exploit unvalidated webhook URLs. This Server-Side Request Forgery (SSRF) vulnerability can lead to unauthorized access to sensitive survey submissions and potential data exfiltration.…