NoSQL Injection Vulnerability in Kibana by Elastic
CVE-2026-63138
6.5MEDIUM
What is CVE-2026-63138?
A vulnerability in Kibana allows authenticated users to exploit NoSQL Injection by injecting specially crafted inputs into the query functionality. This could manipulate query logic, leading to unauthorized data exposure and potentially revealing sensitive information that the user is not permitted to access.
Affected Version(s)
Kibana 9.4.0 <= 9.4.4
Kibana 9.5.0