SB2026090364 - Multiple vulnerabilities in Kibana
Published: September 3, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Incorrect authorization (CVE-ID: CVE-2026-82299)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in Fleet debugging interfaces when exploiting incorrectly configured access control security levels. A remote user can access exposed debugging interfaces to disclose sensitive information.
Only configurations with Fleet debugging interfaces enabled are vulnerable.
2) Missing Authorization (CVE-ID: CVE-2026-78595)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the Kibana Fleet feature when handling Fleet agent data across Kibana spaces. A remote user can enumerate agent metadata and access diagnostic content to disclose sensitive information.
Only deployments with Fleet space awareness enabled and multiple Kibana spaces in use are vulnerable.
3) Incorrect authorization (CVE-ID: CVE-2026-82302)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify configuration without authorization.
The vulnerability exists due to incorrect authorization in Kibana when managing Fleet and agent policy settings. A remote user can exploit incorrectly configured access control security levels to modify configuration without authorization.
Only configurations with Fleet and agent policy management enabled are vulnerable.
4) Incorrect authorization (CVE-ID: CVE-2026-82298)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to incorrect authorization in Kibana when Fleet and agent communication message signing is enabled. A remote user can exploit incorrectly configured access control security levels to cause a denial of service.
Only configurations with Fleet and agent communication message signing enabled are vulnerable.
5) Missing Authorization (CVE-ID: CVE-2026-78596)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify data outside their authorized Kibana space.
The vulnerability exists due to missing authorization in Entity Analytics migration operations when triggering migration operations from a single Kibana space. A remote user can trigger Entity Analytics migration operations to modify data outside their authorized Kibana space.
Only Kibana deployments where the Entity Analytics feature has been initialized in at least one space are affected. Multi-space deployments face broader impact due to the cross-space nature of the operation.
6) Code Injection (CVE-ID: CVE-2026-78593)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify an Elasticsearch ingest pipeline beyond the caller's authorized Elasticsearch permissions.
The vulnerability exists due to improper control of generation of code in Kibana's Cribl integration when processing an insufficiently validated configuration field in a server-side script template. A remote user can inject attacker-controlled expressions to modify an Elasticsearch ingest pipeline beyond the caller's authorized Elasticsearch permissions.
Only deployments with the Cribl integration installed are vulnerable.
7) Incorrect authorization (CVE-ID: CVE-2026-78583)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to incorrect authorization in Kibana Fleet credential minting for enrolled Elastic Agents when processing Elasticsearch cluster privilege declarations from integration packages. A remote user can manipulate input data to cause Elastic Agents on a targeted policy to receive credentials with arbitrarily elevated Elasticsearch cluster privileges.
Only deployments with the Fleet feature enabled and one or more Elastic Agents enrolled are vulnerable.
Remediation
Install update from vendor's website.
References
- https://discuss.elastic.co/t/kibana-9-4-6-9-5-3-security-update-esa-2026-175/390163
- https://discuss.elastic.co/t/kibana-9-4-6-9-5-3-security-update-esa-2026-153/390160
- https://discuss.elastic.co/t/kibana-8-19-22-9-4-6-9-5-3-security-update-esa-2026-178/390164
- https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-174/390162
- https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-154/390161
- https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-151/390159
- https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-140/390158