Authorization bypass through user-controlled key in Kibana - CVE-2026-63259
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through user-controlled key in scheduled query result retrieval functionality when processing user-supplied identifiers that reference scheduled query result data from Kibana Spaces. A remote user can supply crafted identifiers to disclose sensitive information.
Only Kibana deployments with the Osquery Manager integration and multiple Kibana Spaces configured are vulnerable.