ElasticCVE-2026-78606
Elastic Kibana: improper authorization
Medium4.2CVE-2026-78606 · Published Sep 1, 2026 · updated Sep 2, 2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Kibana Product | >= 8.19.11, <= 8.19.20 | No fix yet |
| >= 9.3.0, <= 9.4.5 | No fix yet | |
| >= 9.5.0, <= 9.5.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Elastic advisories
All Elastic| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | Elasticsearch: missing authorization | Medium5.4 | No fix yet |
| Sep 1 | Elastic Kibana: missing authorization | Medium6.5 | No fix yet |
| Sep 1 | Elastic Kibana: path traversal | High7.3 | No fix yet |
| Sep 1 | Elastic Kibana: missing authorization | Medium4.3 | No fix yet |
| Sep 1 | Elastic Kibana: missing authorization | Medium4.3 | No fix yet |
| Sep 1 | Elasticsearch: request smuggling | Medium5.9 | No fix yet |