CVE-2026-63145: Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1...
Added to the CISA Known Exploited Vulnerabilities catalog on 21 Jul 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 4.3.
Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning manag...
Required action: Review and patch if applicable to your AI infrastructure.