MEDIUM
Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
Published Jul 21, 2026
5.0
MEDIUMCVSS 3.1
EPSS 0.29%
Description
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Affected products
-
- Version 8.0.0StatusaffectedConstraints<=8.19.18
- Version 9.0.0StatusaffectedConstraints<=9.3.7
- Version 9.4.0StatusaffectedConstraints<=9.4.3
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-66/388568 Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47578 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-66/388568 | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-47578 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner elastic
Published Jul 21, 2026
Updated Jul 22, 2026
Reserved Jul 15, 2026
Link CVE-2026-63142
CISA Vulnrichment
Updated Jul 22, 2026
ENISA EUVD
EUVD-2026-47578 Assigner elastic
Published Jul 21, 2026
Updated Jul 22, 2026
Exploited since n/a
Link EUVD-2026-47578