PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63145 Elastic CVE debrief

CVE-2026-63145 is an Incorrect Authorization vulnerability in Kibana's Machine Learning functionality. A low-privileged user with Machine Learning access can manipulate Machine Learning audit and notification records for arbitrary jobs by leveraging Kibana's internally elevated credentials. This vulnerability allows unauthorized modification of Machine Learning records, potentially leading to integrity compromise. The vulnerability exists due to insufficient authorization checks in Kibana's Machine Learning management endpoint. Users of Kibana's Machine Learning functionality, especially those with low-privileged access, should be aware of this vulnerability and take necessary actions to protect their systems.

Vendor
Elastic
Product
Kibana
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-03
Advisory published
2026-07-21
Advisory updated
2026-08-03

Who should care

Users of Kibana's Machine Learning functionality, especially those with low-privileged access, should be aware of this vulnerability and take necessary actions to protect their systems. This includes administrators, security teams, and operators who manage or interact with Machine Learning jobs and notifications in Kibana. Additionally, security teams responsible for vulnerability management and incident response should prioritize this vulnerability and plan for mitigation or remediation efforts.

Technical summary

The vulnerability exists in Kibana's Machine Learning management endpoint, which performs an insufficient authorization check. It validates only a coarse privilege level but does not verify that the requesting user has access to specific Machine Learning job or notification resources. This allows a low-privileged user to manipulate Machine Learning audit and notification records for arbitrary jobs, including jobs in other spaces or belonging to other users. The vulnerability can be exploited by leveraging Kibana's internally elevated credentials to write to restricted Machine Learning system indices that the user cannot access directly.

Defensive priority

Medium priority due to the potential for integrity compromise of Machine Learning audit and notification records.

Recommended defensive actions

  • Review and update access controls for Machine Learning functionality in Kibana
  • Implement additional monitoring and logging for Machine Learning audit and notification records
  • Restrict access to sensitive Machine Learning jobs and notifications
  • Apply vendor-provided patches or updates
  • Perform a thorough review of the current Machine Learning job configurations and notification settings
  • Conduct regular security audits to identify potential vulnerabilities in Kibana and its Machine Learning functionality
  • Consider implementing compensating controls, such as role-based access control and segregation of duties

Evidence notes

The CVE record was published on 2026-07-21T23:18:02.460Z and was last modified on 2026-07-22T20:37:38.603Z. The NVD entry is currently Awaiting Analysis. There is limited information available about the specific details of this vulnerability, and defenders should verify the affected scope and severity with the vendor. The CVE record does not provide explicit details on how to exploit this vulnerability or its actual impact. However, it is noted that a low-privileged user with Machine Learning access can manipulate Machine Learning audit and notification records for arbitrary jobs by leveraging Kibana's internally elevated credentials. The evidence is based on the CVE record and NVD entry, which may not be comprehensive.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-63145 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-63145

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-63145 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63145

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.