CVE-2026-63142 - Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
CVE ID :CVE-2026-63142
Published : July 21, 2026, 11:18 p.m. | 1 hour, 32 minutes ago
Description :Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 21, 2026, 11:18 p.m. | 1 hour, 32 minutes ago
Description :Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...