CVE-2026-63145 Details
Description
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning management endpoint performs an insufficient authorization check. The endpoint validates only a coarse privilege level but does not verify that the requesting user has access to the specific Machine Learning job or notification resources provided in the request. As a result, a low-privileged user with Machine Learning access in any Kibana space can manipulate Machine Learning audit and notification records for arbitrary jobs—including jobs in other spaces or belonging to other users—by leveraging Kibana's internally elevated credentials to write to restricted Machine Learning system indices that the user cannot access directly.
A vulnerability exists in Elastic Kibana's Machine Learning feature, specifically in versions 8.0.0 prior to 8.19.18 and 9.0.0 prior to 9.3.7 and 9.4.0 prior to 9.4.3. The issue arises from an incorrect authorization check in a Machine Learning management endpoint, which only verifies a user's coarse privilege level without ensuring access to specific Machine Learning jobs or notification resources. This flaw enables low-privileged users with Machine Learning access in any Kibana space to alter audit and notification records for any job, including those in other spaces or belonging to other users. The manipulation is possible by using Kibana's elevated internal credentials to write to restricted Machine Learning system indices that the user cannot access directly.
Users can upgrade to Kibana versions 8.19.19, 9.3.8, or 9.4.4 to address this vulnerability. For those on the 9.5.x release line, this vulnerability has already been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-69/388572 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 7.14.0, < 8.19.19 >= 9.0.0, < 9.3.8 >= 9.4.0, < 9.4.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | Initial Analysis | [email protected] |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |