CVE-2026-33463 Details
Description
Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window, enabling an unauthenticated actor in possession of the token to retrieve the associated content after expiration.
A vulnerability in Kibana related to improper validation of expiration timestamps allowed time-bounded access tokens to be used beyond their intended validity. This flaw enabled an unauthenticated user with the token to access associated content after it had expired, leading to unauthorized information disclosure. The issue affects Kibana versions 8.0.0 prior to 8.19.15 and 9.0.0 prior to 9.3.4. It is relevant for deployments that utilize the public file sharing feature to create time-limited download links.
Users can upgrade to Kibana versions 8.19.16 or 9.3.5. For those unable to upgrade, it is recommended to revoke any active public file share tokens and avoid issuing new ones until after the upgrade. Where possible, restrict file-sharing access to trusted administrators.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/8-19-16-9-3-5-security-update-esa-2026-33/386551 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-672 | Operation on a Resource after Expiration or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 8.0.0, < 8.19.16 >= 9.0.0, < 9.3.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | [email protected] |