# Kibana 9.3.8, 9.4.4 Security Update (ESA-2026-65)

**URL:** <https://discuss.elastic.co/t/kibana-9-3-8-9-4-4-security-update-esa-2026-65/388566>\
**Category:** Security Announcements\
**Created:** [July 21, 2026, 9:06pm UTC](https://discuss.elastic.co/t/kibana-9-3-8-9-4-4-security-update-esa-2026-65/388566 "2026-07-21T21:06:07Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cronosda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cronosda/32/147882_2.png) [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Post date:** [July 21, 2026, 9:06pm UTC](https://discuss.elastic.co/t/kibana-9-3-8-9-4-4-security-update-esa-2026-65/388566/1 "2026-07-21T21:06:08Z")

</div>

**Missing Authorization in Kibana Leading to Unauthorized Access to Cloud Connect Management Functions**

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

**Affected Versions:**

- 9.x:
  - All versions from 9.3.0 up to and including 9.3.7
  - All versions from 9.4.0 up to and including 9.4.3

Users on the 8.x release line are not affected. The Cloud Connect functionality that contains this vulnerability was introduced in 9.3.0 and is not present in 8.x.

Users on the 9.5.x release line are not affected. The fix was included in 9.5.0, the initial release of this line, before it was publicly available.

**Affected Configurations:**

- Kibana deployments where the Cloud Connect feature is enabled and an administrator has completed the Cloud Connect setup. Deployments that have not enabled or configured Cloud Connect are not affected.

**Solutions and Mitigations:**

The issue is resolved in Kibana 9.3.8 and 9.4.4. Users are encouraged to upgrade to one of these versions or later.

**For Users that Cannot Upgrade:**

- **Self-Managed:** Organizations that do not require Cloud Connect functionality can disable the Cloud Connect feature in their Kibana configuration to eliminate exposure.

- **Cloud Hosted:** Contact Elastic Support for guidance on disabling the Cloud Connect feature if an immediate upgrade is not possible.

**Indicators of Compromise (IOC)**

No specific indicators of compromise have been identified for this vulnerability.

**Elastic Cloud Serverless**

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

**Severity:** CVSSv3.1: Medium ( 6.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L  
**CVE ID:** CVE-2026-63141  
**Problem Type:** CWE-862 - Missing Authorization
