CVE-2026-63145
Last modified
CVE-2026-63145 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning management endpoint performs an insufficient authorization check. The endpoint validates only a coarse privilege level but does not verify that the requesting user has access to the specific Machine Learning job or notification resources provided in the request. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning management endpoint performs an insufficient authorization check. The endpoint validates only a coarse privilege level but does not verify that the requesting user has access to the specific Machine Learning job or notification resources provided in the request. As a result, a low-privileged user with Machine Learning access in any Kibana space can manipulate Machine Learning audit and notification records for arbitrary jobs—including jobs in other spaces or belonging to other users—by leveraging Kibana's internally elevated credentials to write to restricted Machine Learning system indices that the user cannot access directly.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 9.4.0, <= 9.4.3; >= 9.0.0, <= 9.3.7; >= 8.0.0, <= 8.19.18 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-63145?
How severe is CVE-2026-63145?
How do I fix CVE-2026-63145?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6314Out of bounds write in GPU in Google Chrome prior to 147.0.7…8.3
- CVE-2026-63140Reachable Assertion (CWE-617) in Elasticsearch can lead to d…6.5
- CVE-2026-63141Missing Authorization (CWE-862) in Kibana allows an authenti…6.3
- CVE-2026-63142Incomplete List of Disallowed Inputs (CWE-184) in Kibana can…5
- CVE-2026-63143Missing Authorization (CWE-862) in Kibana can lead to unauth…4.3
- CVE-2026-63144Uncontrolled Recursion (CWE-674) in Elasticsearch can lead t…6.5
- CVE-2026-6315Use after free in Permissions in Google Chrome on Android pr…8.8
- CVE-2026-6316Use after free in Forms in Google Chrome prior to 147.0.7727…8.8
- CVE-2026-6317Use after free in Cast in Google Chrome prior to 147.0.7727.…8.8
- CVE-2026-63175PlaywrightCapture stored capture-specific configuration and …7.1
- CVE-2026-6318Use after free in Codecs in Google Chrome prior to 147.0.772…8.8
- CVE-2026-6319Use after free in Payments in Google Chrome on Android prior…7.5
Are you affected by CVE-2026-63145?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
