Description
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the Metrics Experience feature did not enforce a Kibana-level authorization check that an equivalent, related API in the same feature did enforce. As a result, a user who held only data-store-level read access to an index, but no corresponding Kibana feature privilege, could retrieve index-derived metric data through Kibana that the properly-authorized API would otherwise have blocked.
Published: 2026-10-06
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Kibana’s Metrics Experience feature contains an internal API that lacks the required Kibana‑level authorization check. When an authenticated user possesses only data‑store‑read access to an index and does not hold the related Kibana privilege, they can call the unprotected endpoint and receive metric data derived from that index. This allows the disclosure of sensitive metric information that a properly protected API would otherwise hide. The weakness is classified as Missing Authorization (CWE‑862).

Affected Systems

The product affected is Elastic Kibana. The advisory does not list a specific vulnerable version; check the Elastic discussion thread linked in the references for the exact releases that contain the fix, and update accordingly.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires legitimate authentication within Kibana and data‑store‑read permissions. Attackers would simply send a request to the internal metrics endpoint, which is exposed only to Kibana internal traffic. There is no known code execution or denial‑of‑service impact, but the data disclosed can be valuable to an attacker.

Generated by OpenCVE AI on October 6, 2026 at 20:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kibana to the patched release that includes the authorization fix as described in the Elastic discussion thread (the fix appears in Kibana 9.4.1 and later).
  • Adjust Kibana role definitions so that users with data‑store read access also have the required Kibana feature privilege to access metric data, ensuring the authorization guard is exercised.
  • Apply network segmentation or firewall rules to restrict access to the internal Metrics Experience API so that only trusted hosts can reach Kibana’s internal endpoints.

Generated by OpenCVE AI on October 6, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal API surface within the Metrics Experience feature did not enforce a Kibana-level authorization check that an equivalent, related API in the same feature did enforce. As a result, a user who held only data-store-level read access to an index, but no corresponding Kibana feature privilege, could retrieve index-derived metric data through Kibana that the properly-authorized API would otherwise have blocked.
Title Missing Authorization in Kibana Leading to Information Disclosure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:55:18.319Z

Reserved: 2026-09-29T02:06:02.426Z

Link: CVE-2026-102410

cve-icon Vulnrichment

Updated: 2026-10-06T19:55:13.957Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:13.043

Modified: 2026-10-06T20:17:13.043

Link: CVE-2026-102410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:00:06Z

Weaknesses