Executive brief
Kibana, a popular data visualization and management platform, contains a security flaw in its Osquery Manager integration. An authorized user could potentially view scheduled query results from 'Spaces' (isolated work environments) they are not permitted to access by manipulating specific identifiers. This could lead to the unauthorized disclosure of sensitive query data across different organizational departments or projects.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in Kibana's Osquery Manager integration. The vulnerability resides in the functionality used to retrieve scheduled query result data, which fails to properly validate if the requesting user has authorization for the Kibana Space associated with the provided identifier. An attacker with low-privileged network access can supply specific identifiers to reference and disclose data from other Spaces. This issue affects Kibana versions 9.4.0 through 9.4.3 and is resolved in version 9.4.4. Versions prior to 9.4.0 and the 9.5.x branch are not affected.
Affected products
- Elastic Kibana 9.4.0 to 9.4.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory
- 2026-07-21: patched: Fixed in version 9.4.4