Improper Neutralization of Special Elements in Data Query Logic in Kibana - CVE-2026-63138

 

Improper Neutralization of Special Elements in Data Query Logic in Kibana - CVE-2026-63138

Published: September 1, 2026


Vulnerability identifier: #VU146641
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-63138
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements in data query logic in affected query functionality when processing specially crafted input. A remote user can submit specially crafted input that alters the intended query logic to disclose sensitive information.

Only deployments where the affected query management capability is enabled and users have access to the exposed query interfaces are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-63138

Install security update from vendor's website.

Kibana - addressed in versions 9.4.5, 9.5.1

External References

Related Security Bulletins