Missing Authorization in Kibana - CVE-2026-78603

 

Missing Authorization in Kibana - CVE-2026-78603

Published: September 1, 2026


Vulnerability identifier: #VU146639
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78603
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose Fleet deployment metadata.

The vulnerability exists due to missing authorization in Kibana when handling access to Fleet deployment metadata in the default Kibana space. A remote user can bypass Kibana feature authorization and space access controls to disclose Fleet deployment metadata.

Only deployments with native agentless connector infrastructure configured and active Fleet policies present in the default Kibana space are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-78603

Install security update from vendor's website.

Kibana - addressed in versions 9.4.6, 9.5.1

External References

Related Security Bulletins