Improper Neutralization of Special Elements in Data Query Logic in Kibana - CVE-2026-63138
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements in data query logic in affected query functionality when processing specially crafted input. A remote user can submit specially crafted input that alters the intended query logic to disclose sensitive information.
Only deployments where the affected query management capability is enabled and users have access to the exposed query interfaces are vulnerable.