Executive brief
Kibana is a data visualization and management dashboard for the Elastic Stack. A security flaw in the Cloud Connect feature allows logged-in users to view or change cloud configuration settings even if they do not have the specific permissions to do so. This could lead to unauthorized changes to service settings or the exposure of sensitive configuration data.
Technical details
A missing authorization vulnerability (CWE-862) exists in Kibana's Cloud Connect management functions. Authenticated users can bypass intended feature privilege requirements by sending direct requests to insufficiently protected API endpoints. This allows an attacker with low-level access to view or modify Cloud Connect configuration and service settings. The vulnerability affects Kibana versions 9.3.0 through 9.3.7 and 9.4.0 through 9.4.3, specifically where Cloud Connect is enabled and configured. The issue is resolved in Kibana 9.3.8 and 9.4.4.
Affected products
- Elastic Kibana 9.3.0 to 9.3.7, 9.4.0 to 9.4.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory
- 2026-07-21: patched