← Back

CVE-2026-63137

nvd nist
Published: Sep 1, 2026Modified: Sep 2, 2026

JSON object

Loading...
8.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Exploitability: 2.8 / Impact: 5.5
Source: security@elastic.co (Secondary)

Description

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.

Affected (1)

Products: Elastic: Kibana
1 product
Kibana
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 9.3.0 to 9.4.3

References (1)

Timeline

No history available yet.