CVE-2026-78603
Undergoing Analysis
Undergoing Analysis - In Progress
Missing Authorization in Kibana Leads to Information Disclosure
Vulnerability report for CVE-2026-78603, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-01
Last updated on: 2026-09-01
Assigner: Elastic
Description
Description
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| elastic | kibana | From 9.0.0 (inc) to 9.4.5 (inc) |
| elastic | kibana | 9.5.0 |
| elastic | kibana | 9.4.6 |
| elastic | kibana | 9.5.1 |
| elastic | kibana | From 7.0.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |