SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78596

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Kibana is vulnerable due to a missing authorization flaw that allows authenticated users with Security read-level access to perform unauthorized data modifications across all Kibana spaces. This can lead to potential privilege abuse, enabling users to execute privileged write operations beyond their intended access scope. Organizations using Kibana should prioritize addressing this vulnerability to prevent unauthorized data manipulation and ensure proper access controls are enforced.

CVE
CVE-2026-78596
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%

Original NVD Description

Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122). An authenticated user holding Security read-level access in a single Kibana space could trigger Entity Analytics migration operations that perform privileged writes across all Kibana spaces, regardless of that user's actual access scope.