Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-78595
Kibana vulnerability analysis and mitigation

Overview

CVE-2026-78595 is a Missing Authorization vulnerability (CWE-862) in the Kibana Fleet feature that leads to information disclosure via Privilege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agent privileges in one Kibana space can enumerate agent metadata and access diagnostic content belonging to agents enrolled in other Kibana spaces. Affected versions include Kibana 9.1.0 through 9.4.5 and 9.5.0 through 9.5.2. The vulnerability was published on September 3, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Elastic Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) in Kibana's Fleet feature, which fails to enforce space-level isolation when authenticated users query Fleet agent resources. Kibana Spaces are designed to provide logical separation of resources, but the Fleet agent API does not properly validate that the requesting user's privileges are scoped to the space containing the target agents. An attacker with low-privilege (read-level) Fleet agent access in any one space can exploit this by issuing API requests that reference agents enrolled in other spaces, bypassing the intended access boundary. No public proof-of-concept code has been identified (GitHub Advisory, Elastic Advisory).

Impact

Successful exploitation allows an authenticated attacker to enumerate agent metadata and retrieve diagnostic content from Fleet agents enrolled in Kibana spaces they are not authorized to access. The impact is limited to confidentiality — there is no integrity or availability impact. In multi-tenant or enterprise deployments where Kibana Spaces are used to isolate teams or environments, this could expose sensitive operational data such as agent configuration details, host information, and diagnostic artifacts from other organizational units (GitHub Advisory, Elastic Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of publication. The EPSS score is approximately 0.162–0.166%, placing it in the 6th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Elastic Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Kibana deployment running an affected version (9.1.0–9.4.5 or 9.5.0–9.5.2) with the Fleet feature enabled and multi-space configuration in use.
  2. Obtain low-privilege credentials: Acquire or use existing credentials for an account with read-level Fleet agent privileges in at least one Kibana space.
  3. Authenticate to Kibana: Log in to the Kibana instance using the low-privilege account.
  4. Enumerate cross-space agents: Issue Fleet API requests (e.g., against the Fleet agents endpoint) without restricting the query to the authorized space, leveraging the missing authorization check to retrieve agent metadata from other spaces.
  5. Access diagnostic content: Use the same technique to request diagnostic artifacts (e.g., agent diagnostic bundles) belonging to agents in unauthorized spaces, obtaining potentially sensitive operational data (GitHub Advisory, Elastic Advisory).

Indicators of compromise

  • Logs: Kibana audit logs showing a user with Fleet read-level privileges in Space A making API requests to Fleet agent endpoints associated with Space B or other spaces they are not assigned to.
  • Network: Unusual volume of Fleet agent enumeration API calls (e.g., GET /api/fleet/agents) from a single authenticated session, particularly across multiple space contexts.
  • Logs: Access log entries showing requests to Fleet diagnostic download endpoints (e.g., /api/fleet/agents/{agentId}/diagnostics) for agent IDs not belonging to the user's authorized space.

Mitigation and workarounds

Elastic has released patched versions Kibana 9.4.6 and 9.5.3 addressing this vulnerability. Organizations should upgrade to these versions as the primary remediation. As an interim measure, administrators should review and restrict Fleet agent privilege assignments to minimize the number of users with read-level Fleet access, and audit Kibana space configurations to ensure proper isolation. Reviewing audit logs for evidence of unauthorized cross-space agent enumeration is also recommended (Elastic Advisory, GitHub Advisory).

Community reactions

Elastic published a security advisory (ESA-2026-153) disclosing the vulnerability alongside the patched releases. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (Elastic Advisory).

Additional resources


SourceThis report was generated using AI

Related Kibana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-82302HIGH8.1
  • Kibana logoKibana
  • kibana-8.19
NoYesSep 03, 2026
CVE-2026-82299MEDIUM6.5
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesSep 03, 2026
CVE-2026-82298MEDIUM4.3
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesSep 03, 2026
CVE-2026-78596MEDIUM4.3
  • Kibana logoKibana
  • cpe:2.3:a:elastic:kibana
NoYesSep 03, 2026
CVE-2026-78595MEDIUM4.3
  • Kibana logoKibana
  • kibana-9.4
NoYesSep 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management