Description
Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.
Published: 2026-09-26
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Deletion of Data
Action: Assess Impact
AI Analysis

Impact

Missing authorization in Kibana permits an authenticated user with Synthetics privileges scoped to a single space to delete Synthetics monitors that are shared into spaces the user otherwise cannot access, permanently removing those monitors. The same operation can also erase the underlying Elastic Agent integration configuration when the monitor is linked to a private location, bypassing the authorization checks normally performed by Fleet. The deficiency is a classic implementation of missing access control (CWE‑862).

Affected Systems

The vulnerability affects Elastic Kibana, although no specific versions are listed in the advisory. Any deployment that uses Synthetics monitors and allows cross‑space sharing of those monitors with users who have Synthetics privileges is potentially susceptible until a patch is applied.

Risk and Exploitability

The CVSS score of 6.5 signals a moderate severity level. EPSS data is not available and the vulnerability is not included in the CISA KEV catalog, so aggressive exploitation has not been documented. Nonetheless, the attack requires an authenticated user with Synthetics rights, implying that credential compromise or privilege escalation within the organization could enable exploitation. The impact would be loss of monitoring data and possible disruption of Fleet integrations.

Generated by OpenCVE AI on September 26, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana security update when it becomes available
  • Restrict Synthetics privileges to only the spaces in which the monitors are required and disable cross‑space sharing of those monitors
  • Review and tighten Kibana space access control settings, removing any unintended cross‑space permissions

Generated by OpenCVE AI on September 26, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 26 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Sat, 26 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kibana space could permanently delete Synthetics monitors that are shared into spaces they have no access to. Where a monitor is associated with a private location, the same operation also destroys the underlying Elastic Agent integration configuration without the authorization checks that Fleet would otherwise apply.
Title Missing Authorization in Kibana Leading to Unauthorized Deletion of Data
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-26T23:01:13.551Z

Reserved: 2026-08-24T21:13:45.971Z

Link: CVE-2026-78582

cve-icon Vulnrichment

Updated: 2026-09-26T23:01:10.621Z

cve-icon NVD

Status : Received

Published: 2026-09-26T21:16:55.663

Modified: 2026-09-26T23:16:35.920

Link: CVE-2026-78582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T22:45:17Z

Weaknesses