CVE-2024-43706: Elastic Kibana

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

Affected products

  • Elastic Kibana: up to and including 8.12.0

Published 2025-06-10. Last modified 2026-06-17.