CVE-2026-63143
Analyzed Analyzed - Analysis Complete

Missing Authorization in Kibana Leads to Unauthorized Data Access

Vulnerability report for CVE-2026-63143, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-08-03

Assigner: Elastic

Description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-08-03
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
elastic kibana From 9.0.0 (inc) to 9.3.8 (exc)
elastic kibana From 9.4.0 (inc) to 9.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Missing Authorization issue in Kibana that allows users with limited privileges to access workflow execution outputs in their space without proper authorization. The flaw enables unauthorized information disclosure through Privilege Abuse, where sensitive data from workflow steps or connected sources may be exposed to users who should not have access to it.

Detection Guidance

To detect CVE-2026-63143, check if your Kibana version is between 9.3.0-9.3.7 or 9.4.0-9.4.3. Verify if the Agent Builder and Workflows Management features are enabled and if users have agentBuilder:all without workflowsManagement:readExecution privileges.

Impact Analysis

If you use Kibana, an attacker with limited access could exploit this to view sensitive information from workflows or connected data sources that they are not authorized to see. This could lead to data leaks, unauthorized access to confidential details, or compliance violations depending on the exposed data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) or HIPAA (healthcare data privacy) by exposing personal or protected health information to unauthorized users. Compliance may be impacted if the exposed data includes regulated information.

Mitigation Strategies

Update Kibana to the latest patched version immediately to address the missing authorization issue. Review user privileges and restrict access to sensitive workflow execution outputs. Monitor logs for unauthorized access attempts to workflow data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63143. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart