Loading market data...
← Back to CVE feed

CVE-2026-78603

MEDIUM CVSS 4.3 View on NVD ↗

Description

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges could bypass Kibana feature authorization and space access controls, resulting in the unauthorized disclosure of Fleet deployment metadata from the default Kibana space.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

elastic/kibana
Published: Sep 01, 2026 20:17 UTC Modified: Sep 02, 2026 14:52 UTC