CVE-2026-63262: Missing Authorization in Kibana Leading to Information Disclosure
Published Jul 21, 2026
·Updated
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
Affected Software
1 affected component
Elastic Kibana
Event History
Jul 21, 2026
CVE Published
via MITRE·11:07 PM
Data Sourced
via MITRE·11:07 PM
DescriptionSeverityWeakness
Jul 22, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63262?
CVE-2026-63262 has a medium severity rating of 4.3.
2
How does CVE-2026-63262 affect Kibana?
CVE-2026-63262 allows missing authorization to result in unauthorized cross-space information disclosure.
3
What should I do to mitigate CVE-2026-63262?
To mitigate CVE-2026-63262, ensure that proper authorization checks are implemented for space-level access control in Kibana.
4
Is CVE-2026-63262 exploitable?
Yes, CVE-2026-63262 can be exploited via user-supplied input that bypasses the intended access controls.
5
What type of access does CVE-2026-63262 allow attackers?
CVE-2026-63262 allows attackers to access information across different spaces without proper authorization.