ElasticCVE-2026-78603
Elastic Kibana: missing authorization
Medium4.3CVE-2026-78603 · Published Sep 1, 2026 · updated Sep 2, 2026
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Kibana Product | >= 9.0.0, <= 9.4.5 | No fix yet |
| <= 9.5.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More Elastic advisories
All Elastic| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | Elasticsearch: missing authorization | Medium5.4 | No fix yet |
| Sep 1 | Elastic Kibana: missing authorization | Medium6.5 | No fix yet |
| Sep 1 | Elastic Kibana: path traversal | High7.3 | No fix yet |
| Sep 1 | Elastic Kibana: missing authorization | Medium4.3 | No fix yet |
| Sep 1 | Elasticsearch: request smuggling | Medium5.9 | No fix yet |
| Sep 1 | Elastic Kibana: improper authorization | Medium4.2 | No fix yet |