CVE-2026-63137: Elastic Kibana

High severity, CVSS 8.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.

Affected products

  • Elastic Kibana: from 9.3.0, before 9.4.3 (fixed in 9.4.3)

Published 2026-09-01. Last modified 2026-09-02.