SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-63138

MEDIUM · CVSS 6.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kibana is vulnerable to NoSQL Injection due to improper handling of special elements in data query logic, allowing authenticated users to manipulate queries and access unauthorized data. This could lead to significant information disclosure risks, particularly in environments where sensitive data is managed. Organizations utilizing Kibana should prioritize remediation to safeguard against potential data breaches and ensure compliance with data protection standards.

CVE
CVE-2026-63138
Severity
MEDIUM
CVSS
6.5
EPSS
0.34%

Original NVD Description

Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.

Related CVEs

Other vulnerabilities affecting the same vendor(s)