CVE-2016-1000218: Elastic Kibana Reporting
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially-crafted page.
Affected products
- Elastic Kibana Reporting: version 2.4.0 only
Published 2017-06-16. Last modified 2026-06-17.