Missing Authorization in Kibana - CVE-2026-78603
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose Fleet deployment metadata.
The vulnerability exists due to missing authorization in Kibana when handling access to Fleet deployment metadata in the default Kibana space. A remote user can bypass Kibana feature authorization and space access controls to disclose Fleet deployment metadata.
Only deployments with native agentless connector infrastructure configured and active Fleet policies present in the default Kibana space are vulnerable.