Description
An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized Elasticsearch permissions.
Published: 2026-09-03
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Kibana's Cribl integration permits an authenticated user with Fleet management privileges to inject attacker-controlled expressions into a server-side script template. This injection creates an Elasticsearch ingest pipeline that can be written outside the caller’s authorized permissions, effectively allowing the user to elevate privileges on the Elasticsearch cluster.

Affected Systems

The affected product is Elastic Kibana. No specific version ranges are listed in the CVE entry, so the risk applies to any installation that includes the vulnerable Cribl integration. The Elastic discussion link references updates for versions 8.19.21, 9.4.6, and 9.5.3, which contain the fix.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity, and there is no EPSS data available. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with Fleet management rights, so the attack vector is internal and necessitates access to Kibana. Once exploited, the attacker can write ingest pipelines beyond their normal permissions, giving them indirect control over data indexing and potential data tampering.

Generated by OpenCVE AI on September 3, 2026 at 19:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Kibana security update referenced in Elastic’s discussion, which covers versions 8.19.21, 9.4.6, and 9.5.3 and fixes the Cribl integration validation flaw.
  • If the Cribl integration is not required, disable or remove it until the patch is applied to eliminate the vulnerability.
  • Restrict Kibana Fleet management privileges to trusted users only and review existing user assignments to limit potential exploitation.
  • Continuously monitor Elasticsearch ingest pipeline creation events for unauthorized or unexpected entries as an additional detection layer.

Generated by OpenCVE AI on September 3, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 03 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized Elasticsearch permissions.
Title Improper Control of Generation of Code in Kibana Leading to Privilege Escalation
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-03T18:49:59.206Z

Reserved: 2026-08-24T21:13:51.299Z

Link: CVE-2026-78593

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:28.687

Modified: 2026-09-03T19:17:28.687

Link: CVE-2026-78593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:00:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')