What is CVE-2026-63142?
An authenticated attacker with access to the Reporting feature in Kibana can bypass outbound request restrictions set by an administrator, allowing the reporting service to send requests to denied network destinations. This is due to an Incomplete List of Disallowed Inputs (CWE-184). It is recommended to update Kibana and review Reporting configurations to mitigate this issue.
Azərbaycanca: Kibana-da "Reporting" funksiyası vasitəsilə autentifikasiya olunmuş hücumçu, admin tərəfindən təyin edilmiş şəbəkə məhdudiyyətlərini keçərək icazəsiz ünvanlara sorğu göndərə bilər. Bu zəiflik CWE-184 (İcazə Verilməyən Girişlərin Natamam Siyahısı) kateqoriyasına aiddir. Təhlükəsizlik tədbiri olaraq Kibana yeniləmələrini tətbiq etmək və Reporting konfiqurasiyalarını nəzərdən keçirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Does exploiting CVE-2026-63142 require the attacker to be authenticated in Kibana?
Yes, this vulnerability can only be exploited by an authenticated attacker who has access to the Reporting feature in Kibana.
What measures are recommended to mitigate CVE-2026-63142?
It is recommended to apply Kibana updates and review Reporting configurations to mitigate this security issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.