Incomplete Input Validation in Kibana Reporting Feature
CVE-2026-63142

5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-63142?

This vulnerability in Kibana arises from an incomplete list of disallowed inputs, which allows an authenticated attacker with access to the Reporting functionality to circumvent outbound request restrictions imposed by the administrator. As a result, the reporting service may issue requests to network resources that should be blocked according to the established security settings. This flaw poses a significant risk, as it enables potential data exfiltration and unauthorized access to external systems.

Affected Version(s)

Kibana 9.4.0 <= 9.4.3

Kibana 8.0.0 <= 8.19.18

Kibana 9.0.0 <= 9.3.7

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.