CVE-2026-33463: Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized File Access
Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window, enabling an unauthenticated actor in possession of the token to retrieve the associated content after expiration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33463?
CVE-2026-33463 has a medium severity rating of 5.3.
What vulnerability does CVE-2026-33463 describe?
CVE-2026-33463 describes a logic error in Kibana that allows unauthorized file access after the expiration of a time-bounded access token.
How do I fix CVE-2026-33463?
To fix CVE-2026-33463, update to the latest version of Elastic Kibana where the expiration logic has been addressed.
What impact does CVE-2026-33463 have on systems using Kibana?
CVE-2026-33463 can lead to unauthorized information disclosure, potentially exposing sensitive data.
Is CVE-2026-33463 related to authentication issues in Kibana?
Yes, CVE-2026-33463 is related to a logic error affecting the validity of time-bounded access tokens in Kibana.