CVE-2026-63145: Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification
Summary
Kibana has an authorization vulnerability (CWE-863, a flaw where access control is not properly enforced) in its Machine Learning feature that allows low-privileged users to modify audit and notification records for ML jobs they shouldn't have access to. The problem occurs because the system checks if a user has general ML permissions but doesn't verify they can access the specific ML job or resource they're trying to modify, letting them exploit Kibana's internal elevated permissions to write to restricted system indices.
Vulnerability Details
4.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
network
low
low
none
July 21, 2026
Classification
Affected Vendors
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63145
First tracked: July 22, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 75%