MEDIUM
Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations
Published Sep 3, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.27%
Description
Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope.
Affected products
-
- Version 8.18.3StatusaffectedConstraints<=8.19.20
- Version 9.0.3StatusaffectedConstraints<=9.4.5
- Version 9.5.0StatusaffectedConstraints<=9.5.2
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner elastic
Published Sep 3, 2026
Updated Sep 3, 2026
Reserved Aug 24, 2026
Link CVE-2026-78596
CISA Vulnrichment
Updated Sep 3, 2026
ENISA EUVD
EUVD-2026-70660 Assigner elastic
Published Sep 3, 2026
Updated Sep 3, 2026
Exploited since n/a
Link EUVD-2026-70660