Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy. | |
| Title | Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-07-21T22:04:28.699Z
Reserved: 2026-07-15T18:23:57.166Z
Link: CVE-2026-63142
No data.
No data.
No data.
OpenCVE Enrichment
No data.