Incorrect authorization in Kibana - CVE-2026-78583
Published: September 3, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to incorrect authorization in Kibana Fleet credential minting for enrolled Elastic Agents when processing Elasticsearch cluster privilege declarations from integration packages. A remote user can manipulate input data to cause Elastic Agents on a targeted policy to receive credentials with arbitrarily elevated Elasticsearch cluster privileges.
Only deployments with the Fleet feature enabled and one or more Elastic Agents enrolled are vulnerable.