Description
Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Published: 2026-09-03
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization flaw (CWE-863) that occurs when Kibana’s access control is improperly configured. Because the system does not correctly enforce user permissions, an attacker can bypass restrictions and trigger a denial‑of‑service condition. The impact is that a single unauthorized request can render Kibana unavailable to legitimate users, compromising availability.

Affected Systems

Elastic Kibana is affected. The information does not list specific software versions, so any installation that uses Kibana may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 4.3 indicates low to moderate severity. The EPSS score is not available, so the exact likelihood of exploitation is unclear, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote exploitation by abusing incorrectly configured access control levels; the attacker requires access to a Kibana instance that has weak or missing authentication.

Generated by OpenCVE AI on September 3, 2026 at 19:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Kibana security update for your deployment.
  • Verify that access control is properly configured by setting appropriate security levels and disabling any default permissive settings.
  • Enforce multi‑factor authentication and least‑privilege principles as recommended by Elastic.
  • Monitor Kibana logs for repeated unauthorized access attempts to detect potential exploitation attempts.

Generated by OpenCVE AI on September 3, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 03 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Title Incorrect Authorization in Kibana Leading to Denial of Service
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-03T18:47:43.061Z

Reserved: 2026-08-28T11:30:29.847Z

Link: CVE-2026-82298

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:29.587

Modified: 2026-09-03T19:17:29.587

Link: CVE-2026-82298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:00:08Z

Weaknesses