← Retour à la recherche de CVE

CVE-2026-63142

Kibana

Description

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.

CVSS 5EPSS 0.172%Risque 0.51
Voir la source
Publication
2026-07-21 23:18:02
Versions concernées
unknown
Type
Application web
Dernière modification
2026-08-03 17:57:11
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N