Incomplete List of Disallowed Inputs in Kibana Leading to Server-Side Request Forgery
Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.
Affected Versions:
- 8.x: All versions from 8.0.0 up to and including 8.19.18
- 9.x:
- All versions from 9.0.0 up to and including 9.3.7
- All versions from 9.4.0 up to and including 9.4.3
Users on the 9.5.x release line are not affected. The fix was incorporated before the initial 9.5.0 release.
Affected Configurations:
- Kibana deployments where the Reporting feature is enabled and administrators have configured host-based deny rules in the screenshotting network policy. Kibana instances without custom host-based outbound request restrictions in the screenshotting network policy are not affected.
Solutions and Mitigations:
The issue is resolved in Kibana 8.19.19, 9.3.8, and 9.4.4.
For Users that Cannot Upgrade:
- There are no workarounds for this vulnerability.
Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.
Elastic Cloud Serverless
Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.
Severity: CVSSv3.1: Medium ( 5.0 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVE ID: CVE-2026-63142
Problem Type: CWE-184 - Incomplete List of Disallowed Inputs