Description
Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows a user with limited privileges in Kibana to access workflow execution outputs that should be restricted. The likely attack vector is via the publicly documented API. By using the publicly documented API, an attacker can retrieve data such as responses from connected data sources, including potentially sensitive information that the caller would not normally be able to see. This flaw does not provide arbitrary code execution or other high‑impact exploits but does leak confidential data that could undermine confidentiality and compromise internal processes.

Affected Systems

The flaw affects Elastic Kibana installations. No specific major or minor version range is listed in the CVE data; however, the Elastic security discussion referenced in the advisory indicates that remediation is available in recent releases. Users should verify which Kibana version they run and determine if they have applied the patch updates outlined by Elastic.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, further implying that active exploitation is not confirmed. Based on the description, it is inferred that the attack path requires authentic access to the Kibana instance via the documented API; an attacker would need at least normal user privileges within a Kibana space to exploit the flaw. The disclosed data could lead to significant confidentiality loss but does not affect availability or integrity.

Generated by OpenCVE AI on August 4, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Elastic’s latest Kibana release that contains the patch addressing the missing authorization flaw (CWE‑862); consult the Elastic update notes for the exact version.
  • If an immediate upgrade is not possible, temporarily restrict or audit the permissions of Kibana users who have access to the workflows API, ensuring only authorized roles can read workflow outputs.
  • Monitor Kibana API logs for anomalous access to workflow outputs and enforce least‑privilege policies until the patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 21 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.
Title Missing Authorization in Kibana Leading to Unauthorized Information Disclosure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-07-22T13:31:18.863Z

Reserved: 2026-07-15T18:23:57.166Z

Link: CVE-2026-63143

cve-icon Vulnrichment

Updated: 2026-07-22T13:31:09.004Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses