Kibana 9.3.8, 9.4.4 Security Update (ESA-2026-65)

Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

Affected Versions:

  • 9.x:
    • All versions from 9.3.0 up to and including 9.3.7
    • All versions from 9.4.0 up to and including 9.4.3

Users on the 8.x release line are not affected. The Cloud Connect functionality that contains this vulnerability was introduced in 9.3.0 and is not present in 8.x.

Users on the 9.5.x release line are not affected. The fix was included in 9.5.0, the initial release of this line, before it was publicly available.

Affected Configurations:

  • Kibana deployments where the Cloud Connect feature is enabled and an administrator has completed the Cloud Connect setup. Deployments that have not enabled or configured Cloud Connect are not affected.

Solutions and Mitigations:

The issue is resolved in Kibana 9.3.8 and 9.4.4. Users are encouraged to upgrade to one of these versions or later.

For Users that Cannot Upgrade:

  • Self-Managed: Organizations that do not require Cloud Connect functionality can disable the Cloud Connect feature in their Kibana configuration to eliminate exposure.

  • Cloud Hosted: Contact Elastic Support for guidance on disabling the Cloud Connect feature if an immediate upgrade is not possible.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVE ID: CVE-2026-63141
Problem Type: CWE-862 - Missing Authorization