CVE-2026-63137: Incorrect Authorization in Kibana Leading to Privilege Escalation

Published Sep 1, 2026
·
Updated

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.

Affected Software

1 affected component
Elastic Kibana

Event History

Sep 1, 2026
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Kibana deployments where users have workflow edit permissions are exposed. The issue requires the presence of scheduled workflows that can execute under a different, higher-privileged user's privileges.

2

What does an attacker need to exploit it?

An attacker needs an existing Kibana account with workflow edit permissions. No user interaction is required, and the vulnerability is network-accessible according to the provided vector.

3

What could an attacker do after exploitation?

The attacker could cause scheduled workflow executions to run with a higher-privileged user's permissions. This can allow access to and modification of data outside the attacker's authorized scope.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203