CVE-2026-63141EPSS p12.6%

CVE-2026-63141CVE-2026-63141

elastic / kibana

Description

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

Scoring

CVSS 6.3 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS0.23% probability of exploitation · percentile 12.6% · 2026-10-05T12:00:23Z
Last modified2026-08-06
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.