Back to CVE List

CVE-2026-63142

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Vulnerability Description

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-863
Source
NVD
Vendor
Elastic
Product
Kibana

External References

Discussion (0)

Add Comment

No comments yet. Be the first!