PatchSiren cyber security CVE debrief
CVE-2026-63145 Elastic CVE debrief
CVE-2026-63145 is an Incorrect Authorization vulnerability in Kibana's Machine Learning functionality. A low-privileged user with Machine Learning access can manipulate Machine Learning audit and notification records for arbitrary jobs by leveraging Kibana's internally elevated credentials. This vulnerability allows unauthorized modification of Machine Learning records, potentially leading to integrity compromise. The vulnerability exists due to insufficient authorization checks in Kibana's Machine Learning management endpoint. Users of Kibana's Machine Learning functionality, especially those with low-privileged access, should be aware of this vulnerability and take necessary actions to protect their systems.
- Vendor
- Elastic
- Product
- Kibana
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Users of Kibana's Machine Learning functionality, especially those with low-privileged access, should be aware of this vulnerability and take necessary actions to protect their systems. This includes administrators, security teams, and operators who manage or interact with Machine Learning jobs and notifications in Kibana. Additionally, security teams responsible for vulnerability management and incident response should prioritize this vulnerability and plan for mitigation or remediation efforts.
Technical summary
The vulnerability exists in Kibana's Machine Learning management endpoint, which performs an insufficient authorization check. It validates only a coarse privilege level but does not verify that the requesting user has access to specific Machine Learning job or notification resources. This allows a low-privileged user to manipulate Machine Learning audit and notification records for arbitrary jobs, including jobs in other spaces or belonging to other users. The vulnerability can be exploited by leveraging Kibana's internally elevated credentials to write to restricted Machine Learning system indices that the user cannot access directly.
Defensive priority
Medium priority due to the potential for integrity compromise of Machine Learning audit and notification records.
Recommended defensive actions
- Review and update access controls for Machine Learning functionality in Kibana
- Implement additional monitoring and logging for Machine Learning audit and notification records
- Restrict access to sensitive Machine Learning jobs and notifications
- Apply vendor-provided patches or updates
- Perform a thorough review of the current Machine Learning job configurations and notification settings
- Conduct regular security audits to identify potential vulnerabilities in Kibana and its Machine Learning functionality
- Consider implementing compensating controls, such as role-based access control and segregation of duties
Evidence notes
The CVE record was published on 2026-07-21T23:18:02.460Z and was last modified on 2026-07-22T20:37:38.603Z. The NVD entry is currently Awaiting Analysis. There is limited information available about the specific details of this vulnerability, and defenders should verify the affected scope and severity with the vendor. The CVE record does not provide explicit details on how to exploit this vulnerability or its actual impact. However, it is noted that a low-privileged user with Machine Learning access can manipulate Machine Learning audit and notification records for arbitrary jobs by leveraging Kibana's internally elevated credentials. The evidence is based on the CVE record and NVD entry, which may not be comprehensive.
Official resources
-
CVE-2026-63145 CVE record
CVE.org
-
CVE-2026-63145 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T23:18:02.460Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.