Kibana 9.4.3 Security Update (ESA-2026-61)

Incorrect Authorization in Kibana Leading to Privilege Escalation

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.

Affected Versions:

  • 9.x: All versions from 9.3.0 up to and including 9.4.2.

Users on the 8.x release line and earlier are not affected. The Workflows feature that contains this vulnerability was introduced in Kibana 9.3.0 and is not present in the 8.x release line.

Affected Configurations:
All deployment types are affected with the Workflows feature enabled.

Solutions and Mitigations:
The issue is resolved in Kibana version 9.4.3.

For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless
Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: High ( 8.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVE ID: CVE-2026-63137
Problem Type: CWE-863 - Incorrect Authorization
Impact: CAPEC-180 - Exploiting Incorrectly Configured Access Control Security Levels