SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-78583

HIGH · CVSS 8.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Kibana is vulnerable to incorrect authorization, allowing users with Fleet management privileges to manipulate input data and escalate their privileges. This flaw enables them to issue credentials to Elastic Agents that can grant elevated Elasticsearch cluster privileges, potentially leading to full cluster administration. Organizations using Kibana and Elastic Agents should prioritize addressing this vulnerability to prevent unauthorized access and control over their Elasticsearch clusters.

CVE
CVE-2026-78583
Severity
HIGH
CVSS
8.1
EPSS
0.22%

Original NVD Description

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges, up to and including full cluster administration.

Related CVEs

Other vulnerabilities affecting the same vendor(s)