CVE-2026-63142 MEDIUM

CVE-2026-63142: Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery

Vendor Elastic
Product Kibana
Weakness CWE-863 · Incorrect authorization
Published July 21, 2026
Last update July 21, 2026

CVSS base score

5.0/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Key dates

02Disclosure timeline

July 21, 2026 CVE published

Related vulnerabilities

04Related CVE