CVE-2026-63259
EUVD-2026-4758521.07.2026, 23:18
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 9.4.0 ≤ 𝑥 < 9.4.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration