Incorrect authorization in Kibana - CVE-2026-78606
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose, modify, and delete data.
The vulnerability exists due to incorrect authorization in Elastic AI Assistant Knowledge Base entries when authenticated principals from different authentication realms share the same username value. A remote user can access the other principal's private knowledge base entries to disclose, modify, and delete data.
Only deployments with multiple authentication realms configured are affected, and the issue requires the principals to hold a role granting access to the Elastic AI Assistant feature.