Back

MEDIUM

Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations

Published Sep 3, 2026

Description

Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner elastic
Published Sep 3, 2026
Updated Sep 3, 2026
Reserved Aug 24, 2026
CISA Vulnrichment
Updated Sep 3, 2026
NVD
Status Undergoing Analysis
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner elastic
Published Sep 3, 2026
Updated Sep 3, 2026
Exploited since n/a
EUVD-2026-70660