CVE-2026-78583: Elastic Kibana
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.
Affected products
- Elastic Kibana: from 8.0.0, before 8.19.21 (fixed in 8.19.21); from 9.0.0, before 9.4.6 (fixed in 9.4.6); from 9.5.0, before 9.5.3 (fixed in 9.5.3)
Published 2026-09-03. Last modified 2026-09-08.