CVE-2026-78581
Received Received - Intake

Authorization Bypass in Kibana via AI Assistant Conversation ID

Vulnerability report for CVE-2026-78581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: Elastic

Description

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify a conversation they do not own. Successful exploitation requires knowledge of a hard-to-guess identifier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
elastic kibana *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Authorization Bypass Through User-Controlled Key in Kibana, classified under CWE-639. It allows an authenticated user to access or modify another user's AI Assistant conversation by referencing a hard-to-guess identifier. This occurs due to improper access control checks.

Detection Guidance

Detection requires monitoring for unauthorized access to AI Assistant conversations. Check logs for unusual activity where a user accesses conversations not belonging to them. Look for requests with hard-to-guess identifiers that bypass normal access controls.

Impact Analysis

If exploited, this vulnerability could let an attacker view or alter conversations they do not own, potentially leading to data leaks or unauthorized modifications. However, exploitation requires knowledge of a hard-to-guess identifier, reducing the risk.

Compliance Impact

This vulnerability could violate compliance with GDPR or HIPAA by allowing unauthorized access to sensitive data. Organizations using Kibana may need to implement additional controls to mitigate risks and ensure regulatory adherence.

Mitigation Strategies

Apply the latest Kibana security patches immediately. Review and enforce strict access controls for AI Assistant conversations. Disable or restrict access to conversation identifiers until a fix is applied. Monitor for suspicious activity and unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart