Loading market data...
← Back to CVE feed

CVE-2026-78606

MEDIUM CVSS 4.2 View on NVD ↗

Description

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Where two authenticated principals originating from different authentication realms share the same username value, one could read, modify, and delete the other's private Elastic AI Assistant Knowledge Base entries.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected Products

elastic/kibana
Published: Sep 01, 2026 20:17 UTC Modified: Sep 02, 2026 14:52 UTC