{"data":{"id":"2a3d0e85-46f3-4449-8fa6-99101d617408","title":"CVE-2026-63145: Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification ","summary":"Kibana has an authorization vulnerability (CWE-863, a flaw where access control is not properly enforced) in its Machine Learning feature that allows low-privileged users to modify audit and notification records for ML jobs they shouldn't have access to. The problem occurs because the system checks if a user has general ML permissions but doesn't verify they can access the specific ML job or resource they're trying to modify, letting them exploit Kibana's internal elevated permissions to write to restricted system indices.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63145","publishedAt":"2026-07-21T23:18:02.460Z","cveId":"CVE-2026-63145","cweIds":["CWE-863"],"cvssScore":"4.3","cvssSeverity":"medium","severity":"medium","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Kibana","Elastic"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-21T23:18:02.460Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}