Authorization Flaw in Kibana Affects Elastic Products
CVE-2026-63141
6.3MEDIUM
What is CVE-2026-63141?
In Kibana, an authorization vulnerability allows authenticated users to bypass necessary feature privileges, enabling them to directly access and modify Cloud Connect configurations and service settings through unprotected product endpoints. This poses a significant risk as it can lead to unauthorized changes that impact service integrity and security.
Affected Version(s)
Kibana 9.4.0 <= 9.4.3
Kibana 9.3.0 <= 9.3.7