Skip to content
ElasticCVE-2026-63142

Elastic Kibana: improper authorization

Medium5.0CVE-2026-63142 · Published Jul 21, 2026 · updated Aug 3, 2026

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Elastic advisory

Affected versions

PackageAffectedFixed in
Kibana
Product
>= 9.4.0, <= 9.4.3No fix yet
>= 8.0.0, <= 8.19.18No fix yet
>= 9.0.0, <= 9.3.7No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More Elastic advisories

All Elastic
Advisory
Elastic Kibana: missing authorization
Medium4.3Jul 21
Elasticsearch: denial of service
Medium6.5Jul 21
Elastic Kibana: improper authorization
Medium4.3Jul 21
Elastic Kibana: information disclosure
Medium4.3Jul 21
Elastic Kibana: resource exhaustion
Medium6.5Jul 21
Elastic Kibana: resource exhaustion
Medium6.5Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.