Description
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.
Published: 2026-09-01
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Assess Impact
AI Analysis

Impact

Incorrect Authorization (CWE‑863) in Kibana allows an attacker that can authenticate from more than one realm to misuse another user’s privileged data. The flaw is that the system does not properly enforce Access Control Lists when two logged‑in principals share a username. As a result, a user can read, alter, and delete another user’s Elastic AI Assistant Knowledge Base entries, which are intended to be private.

Affected Systems

Environment involves Elastic Kibana. No specific version numbers are supplied, so the vulnerability applies to any deployed instance where multiple authentication realms coexist and users with identical usernames are permitted.

Risk and Exploitability

The CVSS score of 4.2 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation evidence is not yet documented. The likely attack vector requires the attacker to already be authenticated; however, the presence of multiple realms and username collision is a plausible configuration in many deployments, raising the practical risk for misconfigured environments.

Generated by OpenCVE AI on September 2, 2026 at 02:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure that user names are unique across all authentication realms in Kibana to prevent username collision.
  • Implement or verify that Access Control Lists are explicitly applied to AI Assistant Knowledge Base entries before any action is allowed.
  • Keep Kibana updated to the latest security patch once Elastic releases an official fix and apply it immediately.

Generated by OpenCVE AI on September 2, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Wed, 02 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.
Title Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:40:45.659Z

Reserved: 2026-08-24T21:13:52.890Z

Link: CVE-2026-78606

cve-icon Vulnrichment

Updated: 2026-09-01T19:39:59.162Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:23.887

Modified: 2026-09-02T14:52:59.080

Link: CVE-2026-78606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T03:45:04Z

Weaknesses