CVE-2026-63142 PUBLISHED

Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery

Assigner: elastic
Reserved: 15.07.2026 Published: 21.07.2026 Updated: 22.07.2026

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS Score: 5

Product Status

Vendor Elastic
Product Kibana
Versions Default: unaffected
  • affected from 9.4.0 to 9.4.3 (incl.)
  • affected from 8.0.0 to 8.19.18 (incl.)
  • affected from 9.0.0 to 9.3.7 (incl.)

References

Problem Types

  • CWE-863 Incorrect Authorization CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs