Missing Authorization in Kibana - CVE-2026-63262
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the SLO health scan functionality when processing user-supplied input that circumvents space-level access control. A remote user can supply crafted input to disclose sensitive information.
Only deployments with Service Level Objectives features enabled in multi-space environments are vulnerable.