Kibana ML ACL Bypass Enables Audit & Notification Record Manipulation
CVE-2026-63145 Published on July 21, 2026
Incorrect Authorization in Kibana Leading to Machine Learning Audit Log Integrity Compromise
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1).
A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning management endpoint performs an insufficient authorization check. The endpoint validates only a coarse privilege level but does not verify that the requesting user has access to the specific Machine Learning job or notification resources provided in the request. As a result, a low-privileged user with Machine Learning access in any Kibana space can manipulate Machine Learning audit and notification records for arbitrary jobsincluding jobs in other spaces or belonging to other usersby leveraging Kibana's internally elevated credentials to write to restricted Machine Learning system indices that the user cannot access directly.
Vulnerability Analysis
CVE-2026-63145 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-63145 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-63145
Want to know whenever a new CVE is published for Elastic Kibana? stack.watch will email you.
Affected Versions
Elastic Kibana:- Version 9.4.0, <= 9.4.3 is affected.
- Version 9.0.0, <= 9.3.7 is affected.
- Version 8.0.0, <= 8.19.18 is affected.