PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63145 Elastic CVE debrief

CVE-2026-63145 is an Incorrect Authorization vulnerability in Kibana's Machine Learning functionality. A low-privileged user with Machine Learning access can manipulate Machine Learning audit and notification records for arbitrary jobs by leveraging Kibana's internally elevated credentials. This vulnerability allows unauthorized modification of Machine Learning records, potentially leading to integrity compromise. The vulnerability exists due to insufficient authorization checks in Kibana's Machine Learning management endpoint. Users of Kibana's Machine Learning functionality, especially those with low-privileged access, should be aware of this vulnerability and take necessary actions to protect their systems.

Vendor
Elastic
Product
Kibana
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Users of Kibana's Machine Learning functionality, especially those with low-privileged access, should be aware of this vulnerability and take necessary actions to protect their systems. This includes administrators, security teams, and operators who manage or interact with Machine Learning jobs and notifications in Kibana. Additionally, security teams responsible for vulnerability management and incident response should prioritize this vulnerability and plan for mitigation or remediation efforts.

Technical summary

The vulnerability exists in Kibana's Machine Learning management endpoint, which performs an insufficient authorization check. It validates only a coarse privilege level but does not verify that the requesting user has access to specific Machine Learning job or notification resources. This allows a low-privileged user to manipulate Machine Learning audit and notification records for arbitrary jobs, including jobs in other spaces or belonging to other users. The vulnerability can be exploited by leveraging Kibana's internally elevated credentials to write to restricted Machine Learning system indices that the user cannot access directly.

Defensive priority

Medium priority due to the potential for integrity compromise of Machine Learning audit and notification records.

Recommended defensive actions

  • Review and update access controls for Machine Learning functionality in Kibana
  • Implement additional monitoring and logging for Machine Learning audit and notification records
  • Restrict access to sensitive Machine Learning jobs and notifications
  • Apply vendor-provided patches or updates
  • Perform a thorough review of the current Machine Learning job configurations and notification settings
  • Conduct regular security audits to identify potential vulnerabilities in Kibana and its Machine Learning functionality
  • Consider implementing compensating controls, such as role-based access control and segregation of duties

Evidence notes

The CVE record was published on 2026-07-21T23:18:02.460Z and was last modified on 2026-07-22T20:37:38.603Z. The NVD entry is currently Awaiting Analysis. There is limited information available about the specific details of this vulnerability, and defenders should verify the affected scope and severity with the vendor. The CVE record does not provide explicit details on how to exploit this vulnerability or its actual impact. However, it is noted that a low-privileged user with Machine Learning access can manipulate Machine Learning audit and notification records for arbitrary jobs by leveraging Kibana's internally elevated credentials. The evidence is based on the CVE record and NVD entry, which may not be comprehensive.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T23:18:02.460Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.