← לוח פגיעויות

CVE-2026-63141

בינונית 6.3

תיאור (מקור, אנגלית)

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

מדדים

CVSS 3.1
6.3 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-26/7/2026
CWE
CWE-862

קישורים