CVE-2026-63143

MEDIUM

Missing Authorization in Kibana Leading to Unauthorized Information Disclosure

Title source: cna
STIX 2.1

Description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.

Scores

CVSS v3 4.3
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
Elastic/Kibana 9.3.0 - 9.3.7
Elastic/Kibana 9.4.0 - 9.4.3
Published Jul 21, 2026
Tracked Since Jul 22, 2026