CVE-2026-78606
Undergoing Analysis Undergoing Analysis - In Progress

Incorrect Authorization in Kibana Leading to Data Exposure

Vulnerability report for CVE-2026-78606, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Elastic

Description

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
elastic kibana From 8.19.21 (inc)
elastic kibana From 9.4.6 (inc)
elastic kibana From 9.5.2 (inc)
elastic kibana *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78606 is an Incorrect Authorization vulnerability in Kibana versions 8.19.21, 9.4.6, and 9.5.2. It allows unauthorized access to private Elastic AI Assistant knowledge base entries when two authenticated users from different authentication realms share the same username. The flaw occurs because the system does not properly enforce access controls across authentication realms.

Detection Guidance

To detect this vulnerability, check if your Kibana deployment is running versions 8.19.21, 9.4.6, or 9.5.2. Verify if multiple authentication realms exist where users share the same username and have access to the Elastic AI Assistant feature.

Impact Analysis

If you use Kibana in a multi-realm authentication setup where users share usernames, an attacker could access, modify, or delete your private knowledge base entries. This could lead to data leaks, data corruption, or unauthorized changes to your AI Assistant's stored information.

Compliance Impact

This vulnerability could violate compliance requirements for data protection and privacy, such as GDPR or HIPAA, by allowing unauthorized access to sensitive data. Organizations using affected Kibana versions may face compliance violations if user data is exposed or altered due to this flaw.

Mitigation Strategies

Upgrade Kibana to a patched version (8.19.21+, 9.4.6+, or 9.5.2+). If upgrading is not possible, consider disabling the Elastic AI Assistant feature or restricting access to single authentication realms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78606. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart