Description
Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Published: 2026-09-03
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Elastic Kibana has an incorrect authorization flaw (CWE‑863) that allows an attacker to access data they should not see. The vulnerability is tied to incorrectly configured security levels, which may expose sensitive information through CAPEC‑180 patterns. Although the product code is not malicious, the flaw can leak logs, dashboards, or other data that could aid an adversary in mapping or further attacks.

Affected Systems

Elastic Kibana is affected. No specific version range is listed, so all installations using the Kibana component from Elastic may be susceptible until a patch is applied.

Risk and Exploitability

The CVSS v3 score of 6.5 indicates medium severity. EPSS is not available, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting it has not been widely exploited. The likely attack vector is through a misconfigured or partially authenticated user who can trigger the broken authorization logic, especially if role‑based access control is not properly enforced. Once accessed, an attacker can read otherwise protected data.

Generated by OpenCVE AI on September 3, 2026 at 19:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for Kibana from Elastic.
  • Confirm that role‑based access control is enabled and that all users have only the permissions they need.
  • Audit index and dashboard permissions to ensure no unintended visibility is granted to anonymous or low privilege users.

Generated by OpenCVE AI on September 3, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 03 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Title Incorrect Authorization in Kibana Leading to Information Disclosure
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-03T18:47:03.603Z

Reserved: 2026-08-28T11:30:29.847Z

Link: CVE-2026-82299

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:29.707

Modified: 2026-09-03T19:17:29.707

Link: CVE-2026-82299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:00:08Z

Weaknesses