ElasticCVE-2026-63142
Elastic Kibana: improper authorization
Medium5.0CVE-2026-63142 · Published Jul 21, 2026 · updated Aug 3, 2026
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Kibana Product | >= 9.4.0, <= 9.4.3 | No fix yet |
| >= 8.0.0, <= 8.19.18 | No fix yet | |
| >= 9.0.0, <= 9.3.7 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Elastic advisories
All Elastic| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 21 | Elastic Kibana: missing authorization | Medium4.3 | No fix yet |
| Jul 21 | Elasticsearch: denial of service | Medium6.5 | No fix yet |
| Jul 21 | Elastic Kibana: improper authorization | Medium4.3 | No fix yet |
| Jul 21 | Elastic Kibana: information disclosure | Medium4.3 | No fix yet |
| Jul 21 | Elastic Kibana: resource exhaustion | Medium6.5 | No fix yet |
| Jul 21 | Elastic Kibana: resource exhaustion | Medium6.5 | No fix yet |