SB2026090222 - Missing Authorization in Kibana



SB2026090222 - Missing Authorization in Kibana

Published: September 2, 2026

Security Bulletin ID SB2026090222
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Authorization (CVE-ID: CVE-2026-78601)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in Kibana Entity Store configuration operation when processing configuration operations. A remote privileged user can cause a background task to read unauthorized Elasticsearch indices to disclose sensitive information.

Only deployments with a Platinum or higher subscription or equivalent trial license, with Entity Store v2 enabled by an administrator, and where the Entity Store has been installed at least once are affected.


Remediation

Install update from vendor's website.