Missing Authorization in Kibana - CVE-2026-78601
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in Kibana Entity Store configuration operation when processing configuration operations. A remote privileged user can cause a background task to read unauthorized Elasticsearch indices to disclose sensitive information.
Only deployments with a Platinum or higher subscription or equivalent trial license, with Entity Store v2 enabled by an administrator, and where the Entity Store has been installed at least once are affected.