Junglewise Threat Intelligence

CVE-2026-63142: Elastic Kibana SSRF bypass in Reporting feature

CVE-2026-63142 · Severity: medium · CVSS 5 · Published 2026-07-21

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana is a data visualization and exploration tool used to analyze large datasets. A security flaw in its Reporting feature allows authorized users to bypass network restrictions set by administrators. This could allow an attacker to force the server to send requests to internal network locations that should be private, potentially exposing sensitive internal information.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Kibana due to an incomplete list of disallowed inputs (CWE-184) within the Reporting feature. Authenticated attackers with access to Reporting can bypass host-based deny rules configured in the screenshotting network policy. This allows the reporting service to send requests to network destinations that should be restricted by the security policy. The vulnerability requires the Reporting feature to be enabled and custom host-based outbound restrictions to be in place. The issue is resolved in versions 8.19.19, 9.3.8, and 9.4.4.

Affected products

  • Elastic Kibana 8.0.0 to 8.19.18, 9.0.0 to 9.3.7, 9.4.0 to 9.4.3

Timeline

  • 2026-07-21: advisory: Elastic published security update ESA-2026-66
  • 2026-07-21: disclosed

References

Related threats