CVE-2026-63137 is an incorrect authorization vulnerability in Elastic Kibana's scheduled-workflow execution handling. A user granted workflow-edit permissions can cause a scheduled workflow to execute using the permissions of a different, higher-privileged user. This permits the lower-privileged user to operate outside their intended authorization scope.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script (exploit.py) and a README. The script is a standalone, standard-library-only operational PoC for a pre-authenticated remote code execution chain against vulnerable WordPress Core versions. It is not part of a larger exploit framework. Structure and purpose: - README.md documents the vulnerability chain, affected versions, usage, mitigation, and expected output. - exploit.py is the main entry point and implements the full attack workflow plus a re-use mode for an already deployed shell. Main exploit capabilities: 1. Verifies the WordPress REST batch endpoint is reachable and that route-confusion/desynchronization works. 2. Uses nested batch request confusion to bypass schema sanitization and reach the vulnerable WP_Query author_exclude/author__not_in path. 3. Performs UNION-based SQL injection to extract database version, DB user, DB name, table prefix, and administrator credential material reflected in REST JSON responses. 4. Uses the SQLi primitive to create a fresh administrator account by poisoning oEmbed/cache-related rows and triggering a WordPress Customizer changeset publish path that results in wp_insert_user() with administrator role. 5. Logs into wp-admin with the created credentials, uploads a ZIP containing a single-file PHP plugin webshell, activates it, and executes arbitrary OS commands. 6. Supports a re-use mode where the operator supplies prior admin credentials and the deployed plugin path to skip the SQLi/admin-creation phases and directly run commands. Operational characteristics: - Attack vector is remote web/network exploitation over HTTP(S). - The exploit accepts a target URL, command to execute, and an insecure TLS option for self-signed certificates. - It appears to manage cookies/session state for authenticated wp-admin actions and dynamically generates usernames/passwords/plugin slugs. - The payload is basic but functional: a hardcoded PHP webshell plugin uploaded through legitimate WordPress admin functionality. Overall, this is a real exploit repository implementing an end-to-end unauthenticated WordPress RCE chain, not merely a detector or README-only proof.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-accessible Kibana vulnerability requiring low privileges, with high confidentiality and integrity impact and low availability impact under CVSS v3.
An incorrect authorization vulnerability in Kibana scheduled workflows that allows a user with workflow-edit permissions to trigger executions under another, higher-privileged user's permissions, resulting in privilege escalation and unauthorized data access or modification.
A high-severity incorrect-authorization vulnerability in Elastic Kibana that permits a user with workflow-edit permissions to escalate privileges by causing scheduled workflows to execute under another, higher-privileged user's permissions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.