Missing Authorization in Kibana - CVE-2026-78601

 

Missing Authorization in Kibana - CVE-2026-78601

Published: September 2, 2026


Vulnerability identifier: #VU146661
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78601
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in Kibana Entity Store configuration operation when processing configuration operations. A remote privileged user can cause a background task to read unauthorized Elasticsearch indices to disclose sensitive information.

Only deployments with a Platinum or higher subscription or equivalent trial license, with Entity Store v2 enabled by an administrator, and where the Entity Store has been installed at least once are affected.


Affected software

Kibana

How to mitigate CVE-2026-78601

Install security update from vendor's website.

Kibana - update to 9.4.5

External References

Related Security Bulletins