CVE-2026-63142: Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63142?
CVE-2026-63142 has a medium severity rating of 5.
What could an attacker achieve by exploiting CVE-2026-63142?
Exploiting CVE-2026-63142 could allow an authenticated attacker to perform Server-Side Request Forgery by bypassing outbound request restrictions.
Which software is affected by CVE-2026-63142?
CVE-2026-63142 affects Elastic Kibana.
How can I protect my system from CVE-2026-63142?
To protect against CVE-2026-63142, ensure that Kibana is updated to the latest version that addresses this vulnerability.
What is the nature of the vulnerability in CVE-2026-63142?
CVE-2026-63142 involves an incomplete list of disallowed inputs in Kibana, which can facilitate unauthorized outbound requests.