AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-7012

HIGH · CVSS 8.8 EPSS 18.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-06-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-7012
Severity
HIGH
CVSS
8.8
EPSS
18.21%

Original NVD Description

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.