Junglewise Threat Intelligence

CVE-2026-33463: Elastic Kibana unauthorized information disclosure in public file sharing

CVE-2026-33463 · Severity: medium · CVSS 5.3 · Published 2026-05-28

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a data visualization platform, contains a flaw in its public file-sharing feature. This vulnerability allows shared download links to remain active even after they were supposed to expire. An unauthorized person who has access to an expired link could still use it to download sensitive files or data, potentially leading to data exposure.

Technical details

A logic error exists in Kibana's validation of expiration timestamps for public file-sharing tokens (CWE-672). The vulnerability allows an unauthenticated attacker who possesses a previously valid, but now expired, access token to continue retrieving associated content. This occurs because the system fails to properly terminate access once the intended validity window has passed. The issue affects Kibana deployments using the public file-sharing feature. It has been resolved in versions 8.19.16 and 9.3.5.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.15, 9.0.0 to 9.3.4

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: patched: Fixed in versions 8.19.16 and 9.3.5
  • 2026-05-28: advisory

References

Related threats