Back to overview

CVE-2026-63141

MEDIUM
6.3
CVSS 3.1
Description
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

Metadata

CVE ID
CVE-2026-63141
State
PUBLISHED
Assigner
elastic
Reserved
2026-07-15 18:23 UTC
Published
2026-07-21 21:08 UTC
Last updated
2026-07-21 21:08 UTC
Primary CWE
CWE-862
CWE-862 Missing Authorization
Vendor / Product
Elastic / Kibana
Sources
cve.org  ·  NVD

Severity & Metrics

6.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products (1)
VendorProductPlatformVersions
Elastic Kibana 9.4.0 ≤ 9.4.3, 9.3.0 ≤ 9.3.7
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862 Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Back to overview