SB2026072275 - Multiple vulnerabilities in Kibana
Published: July 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 13 vulnerabilities.
1) Missing Authorization (CVE-ID: CVE-2026-63262)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the SLO health scan functionality when processing user-supplied input that circumvents space-level access control. A remote user can supply crafted input to disclose sensitive information.
Only deployments with Service Level Objectives features enabled in multi-space environments are vulnerable.
2) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-63259)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through user-controlled key in scheduled query result retrieval functionality when processing user-supplied identifiers that reference scheduled query result data from Kibana Spaces. A remote user can supply crafted identifiers to disclose sensitive information.
Only Kibana deployments with the Osquery Manager integration and multiple Kibana Spaces configured are vulnerable.
3) Improper access control (CVE-ID: CVE-2026-56146)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify watchlist configuration and disclose sensitive information.
The vulnerability exists due to improper access control in the Entity Analytics Watchlist configuration functionality when handling watchlist operations. A remote user can perform write operations on watchlist data to modify watchlist configuration and disclose sensitive information.
Only deployments with Security Solution features enabled at the Platinum license tier or above are vulnerable, and the information disclosure impact requires the Entity Store feature to be enabled.
4) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-49092)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an unintended proxy or intermediary (confused deputy) in Entity Analytics when processing functionality not properly constrained by access controls. A remote user can trigger processing of data using another user's privileges to disclose sensitive information.
Only deployments with Entity Analytics enabled are vulnerable.
5) Missing Authorization (CVE-ID: CVE-2026-63143)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the workflow execution outputs API when handling requests for workflow execution outputs. A remote user can access workflow execution outputs through the documented API to disclose sensitive information.
Only Kibana deployments running an Enterprise license with both the Agent Builder and Workflows Management features enabled are vulnerable. Affected cases require users to have the agentBuilder:all Kibana feature privilege without the corresponding workflowsManagement:readExecution privilege.
6) Missing Authorization (CVE-ID: CVE-2026-63141)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access and modify Cloud Connect configuration and service settings without the required feature privileges.
The vulnerability exists due to missing authorization in insufficiently protected product endpoints when handling direct requests. A remote user can send direct requests to access and modify Cloud Connect configuration and service settings without the required feature privileges.
Only deployments where the Cloud Connect feature is enabled and an administrator has completed the Cloud Connect setup are vulnerable.
7) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-42397)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Entity Analytics endpoints when handling specially crafted requests containing oversized input values. A remote user can submit a specially crafted request containing an oversized input value to cause a denial of service.
Only deployments that use the affected Entity Analytics functionality are vulnerable.
8) Resource exhaustion (CVE-ID: CVE-2026-63261)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Kibana machine learning feature when handling a specially crafted request. A remote user can send a specially crafted request to cause a denial of service.
Only deployments with the machine learning feature enabled and accessible to authenticated users with low-privileged roles are vulnerable.
9) Resource exhaustion (CVE-ID: CVE-2026-63260)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Kibana when processing a specially crafted oversized request payload. A remote user can send a specially crafted oversized request payload to cause a denial of service.
The issue can exhaust available heap memory in the Kibana process and cause the service to crash.
10) Incorrect authorization (CVE-ID: CVE-2026-63145)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to manipulate machine learning audit and notification records.
The vulnerability exists due to improper access control in a machine learning management endpoint when handling requests for specific machine learning job or notification resources. A remote user can send a specially crafted request to manipulate machine learning audit and notification records.
Only configurations with the machine learning feature enabled are vulnerable.
11) Incomplete List of Disallowed Inputs (CVE-ID: CVE-2026-63142)
CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to send requests to network destinations that should be denied by the configured security policy.
The vulnerability exists due to incomplete list of disallowed inputs in the Reporting feature when processing outbound requests under the screenshotting network policy. A remote user can bypass configured outbound request restrictions to send requests to network destinations that should be denied by the configured security policy.
Only Kibana deployments with the Reporting feature enabled and custom host-based deny rules configured in the screenshotting network policy are vulnerable.
12) Resource exhaustion (CVE-ID: CVE-2026-63139)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Kibana Canvas functionality when handling a specially crafted request. A remote user can send a specially crafted request to cause a denial of service.
The issue can cause the Kibana server process to terminate, resulting in a denial of service for all users of the affected instance.
13) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-56147)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and modify or delete protected case attachments.
The vulnerability exists due to authorization bypass through user-controlled key in Kibana file access authorization logic when handling access to case attachments across feature areas. A remote user can retrieve, modify, or delete case attachments belonging to feature areas they are not authorized to access to disclose sensitive information and modify or delete protected case attachments.
Only deployments where users have been granted Files Management or Shared Images feature access are vulnerable.
Remediation
Install update from vendor's website.
References
- https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-73/388576
- https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-70/388573
- https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-58/388557
- https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-54/388553
- https://discuss.elastic.co/t/kibana-9-3-8-9-4-4-security-update-esa-2026-67/388569
- https://discuss.elastic.co/t/kibana-9-3-8-9-4-4-security-update-esa-2026-65/388566
- https://discuss.elastic.co/t/kibana-9-3-7-9-4-4-security-update-esa-2026-55/388554
- https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-72/388575
- https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-71/388574
- https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-69/388572
- https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-66/388568
- https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-63/388560
- https://discuss.elastic.co/t/kibana-8-19-18-9-3-7-9-4-3-security-update-esa-2026-59/388558