Incorrect authorization in Kibana - CVE-2026-78606

 

Incorrect authorization in Kibana - CVE-2026-78606

Published: September 1, 2026


Vulnerability identifier: #VU146646
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78606
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose, modify, and delete data.

The vulnerability exists due to incorrect authorization in Elastic AI Assistant Knowledge Base entries when authenticated principals from different authentication realms share the same username value. A remote user can access the other principal's private knowledge base entries to disclose, modify, and delete data.

Only deployments with multiple authentication realms configured are affected, and the issue requires the principals to hold a role granting access to the Elastic AI Assistant feature.


Affected software

Kibana

How to mitigate CVE-2026-78606

Install security update from vendor's website.

Kibana - addressed in versions 8.19.21, 9.4.6, 9.5.2

External References

Related Security Bulletins