ZeroHour

CVE-2026-63137

large

Privilege Escalation via Incorrect Authorization in Elastic Kibana Workflows

CVSS 3.1
8.3 high
EPSS
<1%p29
Published
()
Modified
AI analysis

Elastic Kibana contains an incorrect authorization flaw (CWE-863) that permits privilege escalation through scheduled workflow executions. A user holding workflow edit permissions can manipulate a workflow so that its scheduled runs execute with the privileges of a different, higher-privileged user instead of their own context. The attacker thereby gains the ability to access and modify data beyond their authorized scope; the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L, score 8.3) indicates network-based exploitation requiring only low privileges and no user interaction. Any Kibana deployment in which users have been granted workflow edit permissions is plausibly affected, though the specific affected version ranges are not stated in the available data. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists, and EPSS currently puts the 30-day exploitation probability at 0.4%.

What to do: Restrict the workflow edit privilege to trusted administrators and review your Kibana role definitions to see which users currently hold it. Watch for Elastic's advisory on CVE-2026-63137 and upgrade Kibana to the patched release it specifies. Audit recent scheduled workflow executions for runs that occurred under unexpected or higher-privileged user contexts.

Affected
Elastic Kibana
Estimated exposure
largetens of thousands of Kibana deployments (public internet scans show tens of thousands of exposed Kibana instances, with the plausibly affected set narrowed by… — Public internet scans consistently index tens of thousands of exposed Kibana instances and the Elastic Stack's broad enterprise install base implies many more internal deployments, but only deployments granting users workflow edit…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.

Vendors
elastic
Products
kibana
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.