CVE-2026-63137
largePrivilege Escalation via Incorrect Authorization in Elastic Kibana Workflows
Elastic Kibana contains an incorrect authorization flaw (CWE-863) that permits privilege escalation through scheduled workflow executions. A user holding workflow edit permissions can manipulate a workflow so that its scheduled runs execute with the privileges of a different, higher-privileged user instead of their own context. The attacker thereby gains the ability to access and modify data beyond their authorized scope; the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L, score 8.3) indicates network-based exploitation requiring only low privileges and no user interaction. Any Kibana deployment in which users have been granted workflow edit permissions is plausibly affected, though the specific affected version ranges are not stated in the available data. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists, and EPSS currently puts the 30-day exploitation probability at 0.4%.
What to do: Restrict the workflow edit privilege to trusted administrators and review your Kibana role definitions to see which users currently hold it. Watch for Elastic's advisory on CVE-2026-63137 and upgrade Kibana to the patched release it specifies. Audit recent scheduled workflow executions for runs that occurred under unexpected or higher-privileged user contexts.
| Elastic Kibana | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.
- Vendors
- elastic
- Products
- kibana
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.