Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-61/390086 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-01 20:17
Updated : 2026-09-02 14:18
NVD link : CVE-2026-63137
Mitre link : CVE-2026-63137
CVE.ORG link : CVE-2026-63137
JSON object : View
Products Affected
elastic
- kibana
CWE
CWE-863
Incorrect Authorization
