SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-63262

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Kibana is vulnerable due to a missing authorization flaw that allows unauthorized cross-space information disclosure through user-supplied input, bypassing space-level access controls. This could potentially expose sensitive data to users who should not have access to it. Organizations utilizing Kibana should prioritize addressing this vulnerability to mitigate risks related to data exposure and ensure proper access controls are enforced.

CVE
CVE-2026-63262
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%

Original NVD Description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

Related CVEs

Other vulnerabilities affecting the same vendor(s)