Missing Authorization in Kibana - CVE-2026-78582
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to delete Synthetics monitors in unauthorized Kibana spaces.
The vulnerability exists due to missing authorization in Kibana Synthetics monitor deletion functionality when deleting monitors shared across Kibana spaces. A remote user can delete a shared Synthetics monitor from a space they can access to delete it from spaces they cannot access.
When the monitor is associated with a private location, deleting it also destroys the underlying Elastic Agent integration configuration. Exploitation requires Kibana spaces to be in use and monitors to be shared across more than one space.