Authorization bypass through user-controlled key in Kibana - CVE-2026-63259

 

Authorization bypass through user-controlled key in Kibana - CVE-2026-63259

Published: July 22, 2026


Vulnerability identifier: #VU139132
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63259
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through user-controlled key in scheduled query result retrieval functionality when processing user-supplied identifiers that reference scheduled query result data from Kibana Spaces. A remote user can supply crafted identifiers to disclose sensitive information.

Only Kibana deployments with the Osquery Manager integration and multiple Kibana Spaces configured are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-63259

Install security update from vendor's website.

Kibana - update to 9.4.4

External References

Related Security Bulletins