CVE-2026-63259: Authorization Bypass Through User-Controlled Key in Kibana Leading to Information Disclosure
Published Jul 21, 2026
·Updated
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
Affected Software
1 affected component
Elastic Kibana
Event History
Jul 21, 2026
CVE Published
via MITRE·10:37 PM
Data Sourced
via MITRE·10:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63259?
The severity of CVE-2026-63259 is medium with a score of 4.3.
2
What type of vulnerability is CVE-2026-63259?
CVE-2026-63259 is an Authorization Bypass vulnerability that allows information disclosure.
3
How does CVE-2026-63259 affect Kibana?
CVE-2026-63259 allows a user to access unauthorized query result data from Kibana Spaces.
4
How can I mitigate CVE-2026-63259?
To mitigate CVE-2026-63259, ensure proper access controls and validate user input when handling identifiers.
5
What software is impacted by CVE-2026-63259?
CVE-2026-63259 affects Elastic Kibana software.