CVE-2026-63138CWE-943

CVE-2026-63138

Medium · published September 2, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
23.1
In the wild
Unconfirmed
What it is

Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00307 · 23.1th percentile
Weakness
CWE-943 · Improper Neutralization of Special Elements in Data Query Logic
Published
2026-09-02T00:17Z
Affected products (2)
ProductVersionsFixed in
elastic/kibana≥ 9.4.0, < 9.4.59.4.5
elastic/kibanaall versions
References (1)
EPSS history
Timeline
  • 03 SEP 03:31Z
    EPSS moved — → 0%
    epss
  • 01 SEP 19:20Z
    Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure
    cvelistv5