CyberRota Analysis
AI-GeneratedKibana is vulnerable due to a missing authorization flaw that allows unauthorized cross-space information disclosure through user-supplied input, bypassing space-level access controls. This could potentially expose sensitive data to users who should not have access to it. Organizations utilizing Kibana should prioritize addressing this vulnerability to mitigate risks related to data exposure and ensure proper access controls are enforced.
CVE
CVE-2026-63262
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%
Original NVD Description
Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.
Related CVEs
Other vulnerabilities affecting the same vendor(s)