What is CVE-2026-63145?
CVE-2026-63145 is an Incorrect Authorization vulnerability in Kibana's Machine Learning functionality. It can lead to integrity compromise of Machine Learning audit and notification records via accessing functionality not properly constrained by ACLs. Users are advised to update Kibana to the latest patched version.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which functionality of Kibana is affected by CVE-2026-63145?
CVE-2026-63145 is an Incorrect Authorization vulnerability affecting Kibana's Machine Learning functionality.
What integrity could be compromised if CVE-2026-63145 is exploited?
If exploited, CVE-2026-63145 can compromise the integrity of Machine Learning audit and notification records.
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.