SEPTEMBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-63259

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Kibana is vulnerable to an authorization bypass that allows attackers to exploit user-controlled keys, potentially leading to unauthorized access to sensitive scheduled query result data from Kibana Spaces. This vulnerability poses a medium risk of information disclosure, making it critical for organizations using Kibana to prioritize patching and securing their instances. Security teams should assess their configurations and user permissions to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-63259
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

Related CVEs

Other vulnerabilities affecting the same vendor(s)