CVE-2026-63137

8.3

Elastic · Kibana

A privilege escalation vulnerability in Elastic Kibana allows authenticated users with specific permissions to execute workflows with elevated privileges.

Executive summary

Elastic Kibana versions 9.3.0 through 9.4.2 contain an authorization flaw that allows authenticated users to escalate privileges, posing a significant risk to data integrity and confidentiality.

Vulnerability

This vulnerability is an Incorrect Authorization (CWE-863) flaw where a user with workflow edit permissions can force scheduled tasks to execute under the security context of a higher-privileged user. This allows an authenticated attacker to bypass intended access controls and modify sensitive data.

Business impact

The ability for a standard user to perform actions with elevated privileges threatens the entire security model of the Kibana deployment. Successful exploitation could lead to unauthorized data modification, information disclosure, or the corruption of critical system workflows. Given the CVSS score of 8.3, this flaw represents a significant risk to business operations, as it undermines the integrity of internal access controls.

Remediation

Immediate Action: Upgrade to Kibana version 9.4.3 or later as specified in the official Elastic security advisory.

Proactive Monitoring: Review audit logs for unusual scheduled workflow executions or unexpected modifications made by users who do not typically hold administrative rights.

Compensating Controls: Restrict workflow edit permissions to a minimal set of trusted users until the patch can be applied to reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a high risk to organizations relying on Kibana for data management and orchestration. Security teams must prioritize applying the patch to version 9.4.3 immediately to prevent unauthorized privilege escalation and ensure the integrity of workflow operations. Failure to remediate could allow malicious actors to compromise the system from within the existing user base.

More Elastic CVEs

Sources