SB2026090165 - Multiple vulnerabilities in Kibana



SB2026090165 - Multiple vulnerabilities in Kibana

Published: September 1, 2026

Security Bulletin ID SB2026090165
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 11
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 11 vulnerabilities.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-72682)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the Agent Builder feature when handling a specially crafted request. A remote user can submit a specially crafted request to cause a denial of service.

Only Kibana deployments with the Agent Builder feature enabled are vulnerable.


2) Incorrect authorization (CVE-ID: CVE-2026-72633)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disable privilege monitoring for a Kibana space.

The vulnerability exists due to incorrect authorization in Kibana Entity Analytics when handling requests to stop the recurring Privilege Monitoring engine task. A remote user can send a request to stop the task to disable privilege monitoring for a Kibana space.

Exploitation requires read-level Security feature access in the target space, and the Entity Analytics Privilege Monitoring engine must have been initialized.


3) Missing Authorization (CVE-ID: CVE-2026-78603)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose Fleet deployment metadata.

The vulnerability exists due to missing authorization in Kibana when handling access to Fleet deployment metadata in the default Kibana space. A remote user can bypass Kibana feature authorization and space access controls to disclose Fleet deployment metadata.

Only deployments with native agentless connector infrastructure configured and active Fleet policies present in the default Kibana space are vulnerable.


4) Incorrect authorization (CVE-ID: CVE-2026-72641)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify data.

The vulnerability exists due to incorrect authorization in Entity Store maintainer tasks when accessing functionality not properly constrained by ACLs. A remote user can enumerate and change the state of maintainer tasks to modify data.

Only users with Security Solution read access in a Kibana space can exploit the issue, which can silently disable Entity Analytics maintenance for that space.


5) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-63138)

CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements in data query logic in affected query functionality when processing specially crafted input. A remote user can submit specially crafted input that alters the intended query logic to disclose sensitive information.

Only deployments where the affected query management capability is enabled and users have access to the exposed query interfaces are vulnerable.


6) Uncaught Exception (CVE-ID: CVE-2026-72644)

CWE-ID: CWE-248 - Uncaught Exception

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncaught exception in Observability AI Assistant when handling a specially crafted request. A remote user can submit a specially crafted request to cause a denial of service.

Only deployments where the Observability AI Assistant is available and usable are exposed. The feature requires an Enterprise or trial license and a configured generative AI connector.


7) Missing Authorization (CVE-ID: CVE-2026-78597)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to create unauthorized API keys.

The vulnerability exists due to missing authorization in the Kibana Entity Store feature when invoking an administrative operation. A remote user can invoke the administrative operation to create unauthorized API keys.

Only deployments where the Kibana Security Solution is in use and the Entity Store feature is available are exposed.


8) Missing Authorization (CVE-ID: CVE-2026-78608)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in an internal Kibana APM integration function when handling requests to read APM integration data. A remote user can access the function to read APM server credentials and disclose sensitive information.

Only deployments where APM server integrations are configured through Fleet using secret token authentication, or cloud APM standalone setups with a secret token configured, are vulnerable.


9) Incorrect authorization (CVE-ID: CVE-2026-78606)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose, modify, and delete data.

The vulnerability exists due to incorrect authorization in Elastic AI Assistant Knowledge Base entries when authenticated principals from different authentication realms share the same username value. A remote user can access the other principal's private knowledge base entries to disclose, modify, and delete data.

Only deployments with multiple authentication realms configured are affected, and the issue requires the principals to hold a role granting access to the Elastic AI Assistant feature.


10) Execution with unnecessary privileges (CVE-ID: CVE-2026-72654)

CWE-ID: CWE-250 - Execution with Unnecessary Privileges

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to execution with unnecessary privileges in the Kibana machine learning feature when performing an operation available to users with read access to the machine learning feature. A remote user can invoke the operation to disclose sensitive information.

No Elasticsearch cluster or index privileges are required.


11) Improper handling of highly compressed data (CVE-ID: CVE-2026-72628)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in Streams content pack processing when processing specially crafted compressed content. A remote user can supply specially crafted content to cause a denial of service.

Only deployments with Streams enabled and the Streams content packs capability turned on are vulnerable, and neither is enabled in a default installation.


Remediation

Install update from vendor's website.