Missing Authorization in Kibana - CVE-2026-78582

 

Missing Authorization in Kibana - CVE-2026-78582

Published: September 25, 2026


Vulnerability identifier: #VU152229
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78582
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete Synthetics monitors in unauthorized Kibana spaces.

The vulnerability exists due to missing authorization in Kibana Synthetics monitor deletion functionality when deleting monitors shared across Kibana spaces. A remote user can delete a shared Synthetics monitor from a space they can access to delete it from spaces they cannot access.

When the monitor is associated with a private location, deleting it also destroys the underlying Elastic Agent integration configuration. Exploitation requires Kibana spaces to be in use and monitors to be shared across more than one space.


Affected software

Kibana

How to mitigate CVE-2026-78582

Install security update from vendor's website.

Kibana - addressed in versions 8.19.22, 9.4.7, 9.5.3

External References

Related Security Bulletins