Description
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Published: 2026-07-21
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Kibana, an incomplete list of disallowed inputs—identified in the description as CWE‑184 and classified by the vendor as CWE‑863 (Server‑Side Request Forgery)—allows an authenticated attacker who can use the Reporting feature to bypass administrator‑configured outbound request restrictions. The attacker can cause the reporting service to send requests to previously blocked internal or external network destinations, potentially exfiltrating data or enabling further lateral movement.

Affected Systems

Elastic Kibana is affected. All currently deployed instances without the fix may be vulnerable until upgraded.

Risk and Exploitability

The CVSS score of 5 indicates a medium severity impact. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and have Reporting feature permissions; therefore, restricting that role or disabling Reporting can reduce the risk.

Generated by OpenCVE AI on August 4, 2026 at 00:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana security update that incorporates the disallowed input check.
  • Restrict or disable the Reporting feature for users who do not require it to limit authenticated attack surface.
  • Enforce a strict outbound request policy in Kibana’s configuration and verify that all disallowed destinations remain blocked.

Generated by OpenCVE AI on August 4, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 21 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Title Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-22T13:35:35.459Z

Reserved: 2026-07-15T18:23:57.166Z

Link: CVE-2026-63142

cve-icon Vulnrichment

Updated: 2026-07-22T13:33:52.148Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses