Incorrect authorization in Kibana - CVE-2026-63145
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to manipulate machine learning audit and notification records.
The vulnerability exists due to improper access control in a machine learning management endpoint when handling requests for specific machine learning job or notification resources. A remote user can send a specially crafted request to manipulate machine learning audit and notification records.
Only configurations with the machine learning feature enabled are vulnerable.