SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-63141

MEDIUM · CVSS 6.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Kibana contains a missing authorization vulnerability that allows authenticated users to access and modify Cloud Connect configurations and service settings without proper privileges, due to insufficient protection of certain endpoints. This could lead to unauthorized changes and potential disruption of services. Organizations using Kibana should prioritize addressing this issue to safeguard their configurations and maintain proper access controls.

CVE
CVE-2026-63141
Severity
MEDIUM
CVSS
6.3
EPSS
0.19%

Original NVD Description

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

Related CVEs

Other vulnerabilities affecting the same vendor(s)