SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-63137

HIGH · CVSS 8.3 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Kibana is vulnerable to incorrect authorization, allowing users with workflow edit permissions to escalate privileges and execute scheduled workflows under the authority of higher-privileged users. This flaw can lead to unauthorized access and modification of sensitive data, posing a significant risk to data integrity and confidentiality. Organizations using Kibana should prioritize addressing this vulnerability to prevent potential exploitation and safeguard their data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63137
Severity
HIGH
CVSS
8.3
EPSS
0.35%

Original NVD Description

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.

Related CVEs

Other vulnerabilities affecting the same vendor(s)