CVE-2026-78582
Received Received - Intake

Missing Authorization in Kibana Allows Unauthorized Data Deletion

Vulnerability report for CVE-2026-78582, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: Elastic

Description

Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
elastic kibana *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Missing Authorization issue in Kibana that allows an authenticated user with Synthetics privileges to delete monitors they should not have access to. The flaw occurs because access control security levels are incorrectly configured, enabling unauthorized deletion of shared data across spaces. It can also destroy underlying Elastic Agent integration configurations for private locations without proper authorization checks.

Detection Guidance

Detecting this vulnerability requires checking Kibana configurations and user privileges. Review Synthetics privileges scoped to spaces and monitor shared configurations. Check Elastic Agent integration permissions and Fleet authorization settings. No specific commands are provided in the context.

Impact Analysis

An attacker with limited access could permanently delete critical Synthetics monitors, disrupting monitoring and alerting systems. This may lead to undetected outages or performance issues. If monitors use private locations, the attacker could also destroy associated Elastic Agent configurations, requiring full reconfiguration.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized deletion of data. GDPR requires data integrity and access controls, while HIPAA mandates protection against unauthorized alterations or deletions of protected health information. The flaw enables deletion of monitors and configurations without proper authorization checks, potentially violating these requirements.

Mitigation Strategies

Review and restrict Synthetics privileges to prevent unauthorized deletion of monitors. Ensure access controls are correctly configured to enforce proper authorization checks for shared resources.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78582. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart