Junglewise Threat Intelligence

CVE-2026-63262: Elastic Kibana missing authorization in SLO health scan

CVE-2026-63262 · Severity: medium · CVSS 4.3 · Published 2026-07-22

Technologies: Elastic Kibana. Vendors: Elastic.

Executive brief

Kibana, a data visualization and management platform, is affected by a security flaw in its Service Level Objectives (SLO) health scan feature. An authenticated user with basic access to one workspace could bypass security controls to view information in other workspaces they are not authorized to see. This could lead to the unauthorized disclosure of sensitive operational data across different business units or projects.

Technical details

A missing authorization vulnerability exists in the Kibana Service Level Objectives (SLO) health scan functionality. The flaw allows an authenticated attacker with 'slo_read' privileges in at least one Kibana Space to bypass space-level access controls via specially crafted user-supplied input. Successful exploitation enables the attacker to disclose information from other Kibana Spaces to which they do not have legitimate access. The vulnerability was introduced in version 9.4.0 and is resolved in version 9.4.4; users on the 8.x and 9.5.x release lines are not affected.

Affected products

  • Elastic Kibana 9.4.0 to 9.4.3

Timeline

  • 2026-07-21: advisory: Elastic published security update ESA-2026-73
  • 2026-07-21: patched: Issue resolved in Kibana version 9.4.4
  • 2026-07-22: disclosed: CVE published to NVD dataset

References

Related threats