Description
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges by sending direct requests to endpoints that are not properly protected. The flaw enables attackers to change configuration and service settings that manage cloud connectivity, which is a privileged operation. This is a classic privilege‑escalation vulnerability described by CWE-862.

Affected Systems

Elastic Kibana is the affected product. The CVE payload does not specify a version range, so any Kibana deployment that has not applied a remedial update from Elastic may be susceptible.

Risk and Exploitability

The CVSS score of 6.3 denotes moderate severity, while the EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation can be carried out by any authenticated user with valid credentials or a compromised account; the attacker sends requests to Cloud Connect endpoints sufficient to modify configuration, effectively granting unauthorized privilege escalation.

Generated by OpenCVE AI on July 30, 2026 at 16:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to a version that includes the authorization fix released by Elastic.
  • Restrict Cloud Connect administrative privileges to only the accounts that truly require them, enforcing least‑privilege access controls.
  • Disable the Cloud Connect feature for accounts that do not need it or remove the feature from the deployment entirely to reduce the attack surface.
  • Implement monitoring of Cloud Connect configuration changes to detect unauthorized modifications.

Generated by OpenCVE AI on July 30, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.
Title Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-22T19:39:06.627Z

Reserved: 2026-07-15T18:23:57.166Z

Link: CVE-2026-63141

cve-icon Vulnrichment

Updated: 2026-07-22T19:32:03.727Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:30:05Z

Weaknesses