CVE-2026-63145
Kibana vulnerability analysis and mitigation

Overview

CVE-2026-63145 is an Incorrect Authorization (CWE-863) vulnerability in Elastic Kibana's Machine Learning functionality that allows a low-privileged user to compromise the integrity of Machine Learning audit and notification records. A Machine Learning management endpoint performs only a coarse privilege-level check without verifying that the requesting user has access to the specific ML job or notification resources in the request. Affected versions include Kibana 7.14.0–8.19.18, 9.0.0–9.3.7, and 9.4.0–9.4.3. It was published on July 21, 2026, with patches released shortly after. The CVSS v3.1 base score is 4.3 (Medium) (GitHub Advisory, Elastic Advisory).

Technical details

The root cause is CWE-863 (Incorrect Authorization), classified under CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). The vulnerable Machine Learning management endpoint validates only a broad privilege level (i.e., whether the user has any ML access) but fails to perform resource-level authorization checks to confirm the user's access to the specific ML job or notification resource being modified. As a result, an authenticated low-privileged user with ML access in any Kibana space can send crafted requests to the endpoint, which then uses Kibana's internally elevated credentials to write to restricted ML system indices — indices the user cannot access directly. This cross-space privilege escalation path requires only network access and low privileges, with no user interaction needed (GitHub Advisory, Elastic Advisory).

Impact

Successful exploitation allows a low-privileged attacker to manipulate Machine Learning audit and notification records for arbitrary ML jobs — including those in other Kibana spaces or belonging to other users — by abusing Kibana's internally elevated credentials. The primary impact is an integrity compromise of ML audit trails and notification data, which could undermine the reliability of anomaly detection alerts and audit logs used for security monitoring. There is no confidentiality or availability impact reported; however, tampering with audit records could obscure malicious activity or disrupt ML-driven alerting workflows (GitHub Advisory, Elastic Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.152% (6th percentile), indicating a low near-term exploitation probability. CVE-2026-63145 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Elastic Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Kibana instance running a vulnerable version (7.14.0–8.19.18, 9.0.0–9.3.7, or 9.4.0–9.4.3) that is accessible over the network.
  2. Obtain low-privileged credentials: Acquire or use existing credentials for any Kibana user account that has Machine Learning access in at least one Kibana space.
  3. Identify target ML jobs: Enumerate Machine Learning jobs in other spaces or belonging to other users by querying available ML endpoints or through the Kibana UI.
  4. Craft malicious request: Send an authenticated HTTP request to the vulnerable ML management endpoint, specifying the resource identifiers (job IDs or notification resource IDs) of ML jobs in other spaces or owned by other users.
  5. Trigger authorization bypass: The endpoint validates only the coarse ML privilege level of the requesting user and proceeds to use Kibana's internally elevated credentials to write to restricted ML system indices, modifying audit or notification records for the targeted jobs.
  6. Achieve objective: Audit and notification records for arbitrary ML jobs are tampered with, potentially suppressing alerts or falsifying audit trails (GitHub Advisory, Elastic Advisory).

Indicators of compromise

  • Logs: Kibana server logs showing authenticated requests from low-privileged users to ML management endpoints referencing job IDs or notification resources outside their assigned Kibana space.
  • Logs: Elasticsearch audit logs recording writes to ML system indices (e.g., .ml-notifications-*, .ml-anomalies-*) initiated by the Kibana internal service account on behalf of a low-privileged user.
  • Network: Unusual or repeated HTTP requests from a single low-privileged user account targeting ML management API endpoints with varying job IDs across spaces.
  • Application Behavior: Unexpected modifications to ML job notification records or audit entries for jobs not owned by or accessible to the requesting user, detected via ML audit log review.

Mitigation and workarounds

Elastic has released patched versions addressing this vulnerability: Kibana 8.19.19, 9.3.8, and 9.4.4. Users should upgrade to one of these fixed versions as the primary remediation. As a defense-in-depth measure, restrict ML access privileges to only users who require them, and monitor Kibana and Elasticsearch audit logs for anomalous cross-space ML record modifications. No specific configuration-based workaround has been published by Elastic (Elastic Advisory, GitHub Advisory).

Community reactions

Elastic published a security advisory (ESA-2026-69) on their community forum detailing the affected versions and fixed releases. The vulnerability received standard automated coverage from vulnerability tracking services such as VulnDB, Tenable, and OSV. No notable independent researcher commentary or significant social media discussion has been identified beyond routine CVE publication notices.

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72677HIGH7.3
  • Kibana logoKibana
  • kibana-9.3
NoYesAug 13, 2026
CVE-2026-72675HIGH7.1
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72681MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.4
NoYesAug 13, 2026
CVE-2026-72680MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesAug 13, 2026
CVE-2026-72674MEDIUM6.5
  • Kibana logoKibana
  • kibana-9.3
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management