SB2026090222 - Missing Authorization in Kibana
Published: September 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Authorization (CVE-ID: CVE-2026-78601)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in Kibana Entity Store configuration operation when processing configuration operations. A remote privileged user can cause a background task to read unauthorized Elasticsearch indices to disclose sensitive information.
Only deployments with a Platinum or higher subscription or equivalent trial license, with Entity Store v2 enabled by an administrator, and where the Entity Store has been installed at least once are affected.
Remediation
Install update from vendor's website.