Description
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Published: 2026-09-03
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Incorrect Authorization flaw (CWE-863) in Kibana that permits an attacker to alter configuration settings without having proper privileges. By exploiting this weakness, an attacker can modify Kibana's operational parameters, potentially compromising the system's intended behavior. The description identifies the problem as misconfigured access control.

Affected Systems

Elastic Kibana is the affected product. The vendor is Elastic, and the product is Kibana. Specific affected version numbers are not listed in the supplied data, so all currently running versions of Kibana should be considered at risk until a patch is applied.

Risk and Exploitability

The CVSS score is 8.1, which represents a high severity vulnerability. No EPSS score is available, making it unclear how frequently the vulnerability is targeted in the wild. The issue is not listed in the CISA KEV catalog, indicating that known exploitation has not been reported. Based on the description, the likely attack vector is internal or network access to the Kibana interface, where an attacker can use the incorrectly configured access control to modify settings. The weakness is categorized as CWE-863 and is associated with CAPEC-180 (Exploiting Incorrectly Configured Access Control Security Levels).

Generated by OpenCVE AI on September 3, 2026 at 20:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kibana to a version that includes the security fix for this issue.
  • Configure role permissions so that only verified administrators can modify configuration settings, removing overly permissive roles from non-admin accounts.
  • Enable logging of Kibana API requests and audit configuration changes to detect unauthorized modifications.

Generated by OpenCVE AI on September 3, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic kibana
Vendors & Products Elastic
Elastic kibana

Thu, 03 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
Title Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-03T18:46:32.995Z

Reserved: 2026-08-28T11:30:29.848Z

Link: CVE-2026-82302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:29.827

Modified: 2026-09-03T19:17:29.827

Link: CVE-2026-82302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:30:10Z

Weaknesses