Description
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.
Published: 2026-09-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via unauthorized access to Fleet deployment metadata
Action: Apply Vendor Fix
AI Analysis

Impact

A missing authorization check in Kibana allows an authenticated user with minimal Elasticsearch privileges to bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default space. The vulnerability is characterized as Missing Authorization (CWE‑862) and is exploited by leveraging incorrectly configured access control settings (CAPEC‑180).

Affected Systems

Elastic Kibana is affected; the known impacted versions include the 9.4.6 and 9.5.1 releases mentioned in the Elastic advisory. No specific patch or version was listed in the vendor data, but the vulnerability applies to any deployment of Kibana that retains the default space configuration without additional hardening.

Risk and Exploitability

The CVSS base score of 4.3 classifies the flaw as medium severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly disclosed exploit at this time. However, the attack requires only an authenticated session with minimal Elasticsearch rights, a condition that could be met by many users. Based on the description, it is inferred that an attacker could exploit the flaw by sending crafted requests to Kibana endpoints that return Fleet metadata, thereby bypassing intended space and feature restrictions (inferred). The potential impact is the exposure of sensitive deployment details, which could facilitate further reconnaissance or credential theft.

Generated by OpenCVE AI on September 2, 2026 at 02:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to the latest patched release that addresses the missing authorization check.
  • Review and enforce stricter space access controls, ensuring that only privileged users can view Fleet deployment metadata.
  • Audit and monitor Kibana logs for unauthorized access attempts to sensitive deployment data.

Generated by OpenCVE AI on September 2, 2026 at 02:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:9.5.0:*:*:*:*:*:*:*

Wed, 02 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.
Title Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet Deployment Metadata
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:41:05.109Z

Reserved: 2026-08-24T21:13:52.889Z

Link: CVE-2026-78603

cve-icon Vulnrichment

Updated: 2026-09-01T19:41:01.394Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:23.637

Modified: 2026-09-02T14:52:43.100

Link: CVE-2026-78603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:45:04Z

Weaknesses