Missing Authorization in Kibana - CVE-2026-63143

 

Missing Authorization in Kibana - CVE-2026-63143

Published: July 22, 2026


Vulnerability identifier: #VU139135
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63143
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the workflow execution outputs API when handling requests for workflow execution outputs. A remote user can access workflow execution outputs through the documented API to disclose sensitive information.

Only Kibana deployments running an Enterprise license with both the Agent Builder and Workflows Management features enabled are vulnerable. Affected cases require users to have the agentBuilder:all Kibana feature privilege without the corresponding workflowsManagement:readExecution privilege.


Affected software

Kibana

How to mitigate CVE-2026-63143

Install security update from vendor's website.

Kibana - addressed in versions 9.3.8, 9.4.4

External References

Related Security Bulletins