Missing Authorization in Kibana - CVE-2026-63141
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to access and modify Cloud Connect configuration and service settings without the required feature privileges.
The vulnerability exists due to missing authorization in insufficiently protected product endpoints when handling direct requests. A remote user can send direct requests to access and modify Cloud Connect configuration and service settings without the required feature privileges.
Only deployments where the Cloud Connect feature is enabled and an administrator has completed the Cloud Connect setup are vulnerable.