
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78595 is a Missing Authorization vulnerability (CWE-862) in the Kibana Fleet feature that leads to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space can enumerate agent metadata and access diagnostic content belonging to agents enrolled in other Kibana spaces. Affected versions include Kibana 9.1.0 through 9.4.5 and 9.5.0 through 9.5.2. The vulnerability was published on September 3, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is a missing authorization check (CWE-862) in Kibana's Fleet feature, which fails to enforce space-level isolation when authenticated users query Fleet agent resources. Kibana Spaces are designed to provide logical separation of resources, but the Fleet agent API does not properly validate that the requesting user's privileges are scoped to the space containing the target agents. An attacker with low-privilege (read-level) Fleet agent access in any one space can exploit this by issuing API requests that reference agents enrolled in other spaces, bypassing the intended access boundary. No public proof-of-concept code has been identified (GitHub Advisory, Elastic Advisory).
Successful exploitation allows an authenticated attacker to enumerate agent metadata and retrieve diagnostic content from Fleet agents enrolled in Kibana spaces they are not authorized to access. The impact is limited to confidentiality — there is no integrity or availability impact. In multi-tenant or enterprise deployments where Kibana Spaces are used to isolate teams or environments, this could expose sensitive operational data such as agent configuration details, host information, and diagnostic artifacts from other organizational units (GitHub Advisory, Elastic Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of publication. The EPSS score is approximately 0.162–0.166%, placing it in the 6th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Elastic Advisory).
GET /api/fleet/agents) from a single authenticated session, particularly across multiple space contexts./api/fleet/agents/{agentId}/diagnostics) for agent IDs not belonging to the user's authorized space.Elastic has released patched versions Kibana 9.4.6 and 9.5.3 addressing this vulnerability. Organizations should upgrade to these versions as the primary remediation. As an interim measure, administrators should review and restrict Fleet agent privilege assignments to minimize the number of users with read-level Fleet access, and audit Kibana space configurations to ensure proper isolation. Reviewing audit logs for evidence of unauthorized cross-space agent enumeration is also recommended (Elastic Advisory, GitHub Advisory).
Elastic published a security advisory (ESA-2026-153) disclosing the vulnerability alongside the patched releases. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (Elastic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."