CVE-2026-63259

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-21 23:18

Updated : 2026-08-03 17:43


NVD link : CVE-2026-63259

Mitre link : CVE-2026-63259

CVE.ORG link : CVE-2026-63259


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-639

Authorization Bypass Through User-Controlled Key