Incorrect authorization in Kibana - CVE-2026-78583

 

Incorrect authorization in Kibana - CVE-2026-78583

Published: September 3, 2026


Vulnerability identifier: #VU146880
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78583
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to incorrect authorization in Kibana Fleet credential minting for enrolled Elastic Agents when processing Elasticsearch cluster privilege declarations from integration packages. A remote user can manipulate input data to cause Elastic Agents on a targeted policy to receive credentials with arbitrarily elevated Elasticsearch cluster privileges.

Only deployments with the Fleet feature enabled and one or more Elastic Agents enrolled are vulnerable.


Affected software

Kibana

How to mitigate CVE-2026-78583

Install security update from vendor's website.

Kibana - addressed in versions 8.19.21, 9.4.6, 9.5.3

External References

Related Security Bulletins