SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78595

MEDIUM · CVSS 4.3 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in Kibana's Fleet feature allows authenticated users with read-level privileges to access and enumerate agent metadata and diagnostic content from other Kibana spaces, leading to potential information disclosure. This issue arises from a lack of proper authorization checks, enabling privilege abuse. Organizations using Kibana, particularly those managing multiple spaces with varying access levels, should prioritize addressing this vulnerability to safeguard sensitive information.

CVE
CVE-2026-78595
Severity
MEDIUM
CVSS
4.3
EPSS
0.17%

Original NVD Description

Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space could enumerate agent metadata and access diagnostic content belonging to agents enrolled in other Kibana spaces.