Incomplete Input Validation in Kibana Reporting Feature
CVE-2026-63142
5MEDIUM
What is CVE-2026-63142?
This vulnerability in Kibana arises from an incomplete list of disallowed inputs, which allows an authenticated attacker with access to the Reporting functionality to circumvent outbound request restrictions imposed by the administrator. As a result, the reporting service may issue requests to network resources that should be blocked according to the established security settings. This flaw poses a significant risk, as it enables potential data exfiltration and unauthorized access to external systems.
Affected Version(s)
Kibana 9.4.0 <= 9.4.3
Kibana 8.0.0 <= 8.19.18
Kibana 9.0.0 <= 9.3.7