Missing Authorization in Kibana - CVE-2026-78597
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to create unauthorized API keys.
The vulnerability exists due to missing authorization in the Kibana Entity Store feature when invoking an administrative operation. A remote user can invoke the administrative operation to create unauthorized API keys.
Only deployments where the Kibana Security Solution is in use and the Entity Store feature is available are exposed.