Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly cause a background task to read from Elasticsearch indices that user is not authorized to access. Derived entity data from those indices is then exposed through the entity store output.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/kibana-9-4-5-security-update-esa-2026-147/390107 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-02 15:17
Updated : 2026-09-03 13:42
NVD link : CVE-2026-78601
Mitre link : CVE-2026-78601
CVE.ORG link : CVE-2026-78601
JSON object : View
Products Affected
elastic
- kibana
CWE
CWE-862
Missing Authorization
