Operation on a Resource after Expiration or Release in Kibana - CVE-2026-33463
Published: May 29, 2026
Kibana
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to operation on a resource after expiration or termination in Kibana public file sharing when validating expiration timestamps for time-bounded download links. A remote attacker can use an expired token in their possession to disclose sensitive information.
Only deployments that use the public file sharing feature to issue time-bounded download links are affected.