Missing Authorization in Kibana - CVE-2026-78608

 

Missing Authorization in Kibana - CVE-2026-78608

Published: September 1, 2026


Vulnerability identifier: #VU146645
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78608
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in an internal Kibana APM integration function when handling requests to read APM integration data. A remote user can access the function to read APM server credentials and disclose sensitive information.

Only deployments where APM server integrations are configured through Fleet using secret token authentication, or cloud APM standalone setups with a secret token configured, are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-78608

Install security update from vendor's website.

Kibana - addressed in versions 8.19.21, 9.4.6, 9.5.2

External References

Related Security Bulletins