CVE-2026-33463
MEDIUMOperation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized File Access
Title source: cnaDescription
Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window, enabling an unauthenticated actor in possession of the token to retrieve the associated content after expiration.
References (1)
Core 1
Scores
CVSS v3
5.3
EPSS
0.0023
EPSS Percentile
13.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-672
Status
published
Products (3)
Elastic/Kibana
8.0.0 - 8.19.15
elastic/kibana
8.0.0 - 8.19.16
Elastic/Kibana
9.0.0 - 9.3.4
Published
May 28, 2026
Tracked Since
May 29, 2026