Missing Authorization in Kibana - CVE-2026-78608
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in an internal Kibana APM integration function when handling requests to read APM integration data. A remote user can access the function to read APM server credentials and disclose sensitive information.
Only deployments where APM server integrations are configured through Fleet using secret token authentication, or cloud APM standalone setups with a secret token configured, are vulnerable.