← Browse

CVE-2026-63142

Low

No strong exploitation signal.

CVSS base
5.0 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
EPSS — probability of exploitation (30 days)
0.3%
21.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-863
Published 2026-07-21 · modified 2026-08-03

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionNNone
ScopeCChanged
ConfidentialityLLow
IntegrityNNone
AvailabilityNNone

Timeline

Description

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

Affected

elastic

References

Official: NVD · CVE.org