CVE-2026-63143 PUBLISHED

Missing Authorization in Kibana Leading to Unauthorized Information Disclosure

Assigner: elastic
Reserved: 15.07.2026 Published: 21.07.2026 Updated: 22.07.2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor Elastic
Product Kibana
Versions Default: unaffected
  • affected from 9.4.0 to 9.4.3 (incl.)
  • affected from 9.3.0 to 9.3.7 (incl.)

References

Problem Types

  • CWE-862 Missing Authorization CWE

Impacts

  • CAPEC-122 Privilege Abuse