6.5
CVE-2026-63138
- EPSS 0.31%
- Veröffentlicht 01.09.2026 19:20:43
- Zuletzt bearbeitet 02.09.2026 14:12:19
- Erkennungen
Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.23 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-943 Improper Neutralization of Special Elements in Data Query Logic
The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
https://discuss.elastic.co/t/kibana-9-4-5-9-5-1-security-update-esa-2026-168/390082