Description
Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope.
Published: 2026-09-03
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in Kibana (CWE‑862) allows an authenticated user with Security read‑level access in one Kibana space to trigger entity analytics migration operations that perform privileged writes in all Kibana spaces. The result is an unauthorized modification of data beyond the user’s intended scope, undermining data integrity and potentially enabling further exploratory or destructive activity.

Affected Systems

Elastic Kibana is the affected product; specific versions are not listed in the advisory, so all deployments of Kibana are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score is 4.3, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, so current exploitation probability is unclear. Attackers must be authenticated, but the privilege abuse can be exploited by any user with read‑level access, making the attack path relatively straightforward once credentials are possessed.

Generated by OpenCVE AI on September 3, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest patched version of Kibana released by Elastic that addresses this authorization flaw
  • Restrict or remove the ability for users with read‑level security permissions to trigger entity analytics migration operations by reviewing and tightening role definitions
  • Enable comprehensive audit logging for migration operations to detect and respond to any unauthorized activity promptly

Generated by OpenCVE AI on September 3, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 03 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope.
Title Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-03T18:48:09.486Z

Reserved: 2026-08-24T21:13:51.299Z

Link: CVE-2026-78596

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:28.993

Modified: 2026-09-03T19:17:28.993

Link: CVE-2026-78596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:30:10Z

Weaknesses