PatchSiren cyber security CVE debrief
CVE-2026-63142 Elastic CVE debrief
CVE-2026-63142 is an Incomplete List of Disallowed Inputs vulnerability in Kibana. An authenticated attacker with access to the Reporting feature can bypass outbound request restrictions configured by an administrator. This causes the reporting service to send requests to network destinations that should be denied by the configured security policy. The vulnerability is classified under CWE-184 and affects Kibana's handling of disallowed inputs.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Users of Kibana, especially those with the Reporting feature enabled, should be aware of this vulnerability. Administrators who have configured security policies for outbound requests are at risk if their configurations do not account for this issue. Affected operators, platform administrators, vulnerability management teams, and security teams should review their configurations and implement necessary mitigations.
Technical summary
The vulnerability, classified under CWE-184, exists in Kibana's handling of disallowed inputs. Specifically, it allows an authenticated attacker with Reporting feature access to circumvent restrictions on outbound requests. This could lead to unauthorized requests being sent to denied network destinations, potentially bypassing security policies set by administrators. The issue arises from an incomplete list of disallowed inputs, which can be exploited by an attacker to send requests to network destinations that should be denied by the configured security policy.
Defensive priority
Medium priority due to the requirement for authentication and access to the Reporting feature.
Recommended defensive actions
- Review and update Kibana configurations to ensure that security policies for outbound requests are comprehensive and account for this vulnerability.
- Implement additional monitoring to detect and respond to potential unauthorized requests.
- Consider applying compensating controls, such as network restrictions or enhanced logging, until an official patch is available.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-07-21T23:18:02.110Z and was last modified on 2026-07-22T20:37:38.603Z. The NVD entry is currently Awaiting Analysis. Evidence is based on the official CVE record and a source reference from Elastic. The vulnerability has been identified in Kibana, and it allows an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator.
Official resources
-
CVE-2026-63142 CVE record
CVE.org
-
CVE-2026-63142 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T23:18:02.110Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.