Description
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.
Published: 2026-09-01
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Elastic Kibana suffers from an incorrect authorization flaw that allows a user with workflow edit permissions to execute scheduled workflow tasks under the identity of a higher‑privileged user. By triggering the workflow, the attacker can read or modify data beyond the scope of their own access, effectively bypassing authorization limits. This issue is classified as CWE‑863, Incorrect Authorization.

Affected Systems

The affected product is Elastic Kibana. No specific version numbers are listed in the CNA data, so all installations of Kibana should be considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity. The EPSS score is not available, so the probability of exploitation cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be intra‑network or internal, requiring an authenticated session with workflow edit rights. Once the attacker has such a session, they can trigger a scheduled workflow to run under another user’s privileges, allowing them to gain unauthorized access to data and functions.

Generated by OpenCVE AI on September 2, 2026 at 00:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch from Elastic for Kibana to address the incorrect authorization flaw.
  • Ensure that users are granted workflow edit permissions only if absolutely necessary and adhere to the principle of least privilege.
  • Review and tighten scheduled workflow execution settings to prevent execution under higher‑privileged identities by unauthorised users.
  • If upgrading immediately is not feasible, disable scheduled workflow execution for all users except those explicitly permitted by the organization’s security policy.

Generated by OpenCVE AI on September 2, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Wed, 02 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.
Title Incorrect Authorization in Kibana Leading to Privilege Escalation
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T03:55:57.724Z

Reserved: 2026-07-15T18:23:57.166Z

Link: CVE-2026-63137

cve-icon Vulnrichment

Updated: 2026-09-01T19:38:21.364Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:15.117

Modified: 2026-09-02T14:18:25.390

Link: CVE-2026-63137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T01:00:07Z

Weaknesses