Missing Authorization in Kibana - CVE-2026-78595
Published: September 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the Kibana Fleet feature when handling Fleet agent data across Kibana spaces. A remote user can enumerate agent metadata and access diagnostic content to disclose sensitive information.
Only deployments with Fleet space awareness enabled and multiple Kibana spaces in use are vulnerable.