CVE-2026-63142
5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Summary
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Kibana | 9.4.0 <= 9.4.3 | affected |
| Elastic | Kibana | 8.0.0 <= 8.19.18 | affected |
| Elastic | Kibana | 9.0.0 <= 9.3.7 | affected |
Weaknesses
- CWE-863: CWE-863 Incorrect Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.