SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-63142

MEDIUM · CVSS 5 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Kibana's Reporting feature contains an incomplete list of disallowed inputs, enabling authenticated attackers to bypass outbound request restrictions set by administrators. This vulnerability could lead to unauthorized network requests, potentially exposing sensitive data or services that should be protected by security policies. Organizations using Kibana, especially those with reporting capabilities, should prioritize addressing this issue to mitigate potential security risks.

CVE
CVE-2026-63142
Severity
MEDIUM
CVSS
5
EPSS
0.17%

Original NVD Description

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Related CVEs

Other vulnerabilities affecting the same vendor(s)