Missing Authorization in Kibana - CVE-2026-63143
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the workflow execution outputs API when handling requests for workflow execution outputs. A remote user can access workflow execution outputs through the documented API to disclose sensitive information.
Only Kibana deployments running an Enterprise license with both the Agent Builder and Workflows Management features enabled are vulnerable. Affected cases require users to have the agentBuilder:all Kibana feature privilege without the corresponding workflowsManagement:readExecution privilege.