Incomplete List of Disallowed Inputs in Kibana - CVE-2026-63142
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to send requests to network destinations that should be denied by the configured security policy.
The vulnerability exists due to incomplete list of disallowed inputs in the Reporting feature when processing outbound requests under the screenshotting network policy. A remote user can bypass configured outbound request restrictions to send requests to network destinations that should be denied by the configured security policy.
Only Kibana deployments with the Reporting feature enabled and custom host-based deny rules configured in the screenshotting network policy are vulnerable.