CVE-2026-63143: Missing Authorization in Kibana Leading to Unauthorized Information Disclosure
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63143?
The severity of CVE-2026-63143 is medium with a CVSS score of 4.3.
What type of vulnerability is CVE-2026-63143?
CVE-2026-63143 is a Missing Authorization vulnerability in Kibana.
How does CVE-2026-63143 affect Kibana users?
CVE-2026-63143 allows users with limited feature privileges to access unauthorized workflow execution outputs.
How can I mitigate CVE-2026-63143?
To mitigate CVE-2026-63143, ensure that proper authorization checks are implemented for accessing sensitive workflow execution outputs.
What versions of Kibana are affected by CVE-2026-63143?
CVE-2026-63143 affects specific versions of Elastic Kibana prior to the security update.