Missing Authorization in Kibana - CVE-2026-63141

 

Missing Authorization in Kibana - CVE-2026-63141

Published: July 22, 2026


Vulnerability identifier: #VU139136
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63141
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access and modify Cloud Connect configuration and service settings without the required feature privileges.

The vulnerability exists due to missing authorization in insufficiently protected product endpoints when handling direct requests. A remote user can send direct requests to access and modify Cloud Connect configuration and service settings without the required feature privileges.

Only deployments where the Cloud Connect feature is enabled and an administrator has completed the Cloud Connect setup are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-63141

Install security update from vendor's website.

Kibana - addressed in versions 9.3.8, 9.4.4

External References

Related Security Bulletins